CVE-2024-0333Google Chrome vulnerability

7 documents7 sources
Severity
5.3MEDIUMNVD
EPSS
0.1%
top 77.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateFeb 1

Description

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages3 packages

CVEListV5google/chrome120.0.6099.216120.0.6099.216
NVDgoogle/chrome< 120.0.6099.216
Debianchromium/chromium< 120.0.6099.216-1~deb11u1+3

Also affects: Fedora 38, 39

🔴Vulnerability Details

3
GHSA
GHSA-238j-9f3m-57fr: Insufficient data validation in Extensions in Google Chrome prior to 1202024-01-11
CVEList
CVE-2024-0333: Insufficient data validation in Extensions in Google Chrome prior to 1202024-01-10
OSV
CVE-2024-0333: Insufficient data validation in Extensions in Google Chrome prior to 1202024-01-10

📋Vendor Advisories

3
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2024-03332024-02-01
Microsoft
Chromium: CVE-2024-0333 Insufficient data validation in Extensions2024-01-09
Debian
CVE-2024-0333: chromium - Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099....2024
CVE-2024-0333 — Google Chrome vulnerability | cvebase