CVE-2024-9956 — Improper Privilege Management in Google Chrome
10 documents10 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 94.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateJan 27
Description
Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
3OSV▶
CVE-2024-9956: Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130↗2024-10-15
CVEList▶
CVE-2024-9956: Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130↗2024-10-15
GHSA▶
GHSA-w2p9-j475-2wp5: Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130↗2024-10-15
📋Vendor Advisories
5Debian▶
CVE-2024-9956: chromium - Inappropriate implementation in WebAuthentication in Google Chrome on Android pr...↗2024
💬Community
1Bugzilla▶
A vulnerability in Firefox mobile allows attackers to trigger fido:/ links, hijacking FIDO2 accounts by tricking victims into authenticating malicious requests, bypassing 2FA, and taking over accounts↗2024-10-02