cbcvebase.
CVE-2024-9956
published 2024-10-15

CVE-2024-9956: Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

Affected

11 ranges
VendorProductVersion rangeFixed in
appleios_18.3_and_ipados
chromiumchromium>= 0 < 130.0.6723.58-1~deb12u1130.0.6723.58-1~deb12u1
chromiumchromium>= 0 < 130.0.6723.58-1130.0.6723.58-1
chromiumchromium>= 0 < 130.0.6723.58-1130.0.6723.58-1
debianchromium< chromium 130.0.6723.58-1~deb12u1 (bookworm)chromium 130.0.6723.58-1~deb12u1 (bookworm)
debianfirefox< chromium 130.0.6723.58-1~deb12u1 (bookworm)chromium 130.0.6723.58-1~deb12u1 (bookworm)
googlechrome< 130.0.6723.58130.0.6723.58
googlechrome>= 130.0.6723.58 < 130.0.6723.58130.0.6723.58
mozillafirefox
msrcmicrosoft_edge
paloaltoprisma_browser

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH