CVE-2024-8906
published 2024-09-17CVE-2024-8906: Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to…
medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_tahoe | — | — |
| apple | safari | — | — |
| chromium | chromium | >= 0 < 129.0.6668.58-1~deb12u1 | 129.0.6668.58-1~deb12u1 |
| chromium | chromium | >= 0 < 129.0.6668.58-1 | 129.0.6668.58-1 |
| chromium | chromium | >= 0 < 129.0.6668.58-1 | 129.0.6668.58-1 |
| debian | chromium | < chromium 129.0.6668.58-1~deb12u1 (bookworm) | chromium 129.0.6668.58-1~deb12u1 (bookworm) |
| chrome | < 129.0.6668.58 | 129.0.6668.58 | |
| chrome | >= 129.0.6668.58 < 129.0.6668.58 | 129.0.6668.58 | |
| msrc | microsoft_edge | — | — |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv4.3MEDIUM