CVE-2024-6995

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

History

07 Aug 2024, 20:35

Type Values Removed Values Added
CWE CWE-358

07 Aug 2024, 19:55

Type Values Removed Values Added
CPE cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
References () https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html - () https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html - Release Notes
References () https://issues.chromium.org/issues/343938078 - () https://issues.chromium.org/issues/343938078 - Permissions Required
Summary
  • (es) La implementación inapropiada en pantalla completa en Google Chrome en Android anterior a 127.0.6533.72 permitió a un atacante remoto que convenció a un usuario a realizar gestos de interfaz de usuario específicos para falsificar el contenido del Omnibox (barra de URL) a través de una página HTML manipulada. (Severidad de seguridad de Chromium: media)
CWE NVD-CWE-noinfo
First Time Google android
Google
Google chrome
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 4.7

06 Aug 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

06 Aug 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-06 16:15

Updated : 2024-08-07 20:35


NVD link : CVE-2024-6995

Mitre link : CVE-2024-6995

CVE.ORG link : CVE-2024-6995


JSON object : View

Products Affected

google

  • android
  • chrome
CWE
NVD-CWE-noinfo CWE-358

Improperly Implemented Security Check for Standard