4.3
CVSSv3

CVE-2024-0810

Published: 24/01/2024 Updated: 29/01/2024
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Insufficient policy enforcement in DevTools in Google Chrome before 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

The Stable channel has been updated to 1210616785 for Mac and Linux and 1210616785/86 to Windows which will roll out over the coming days/weeks A full list of changes in this build is available in the logSecurity Fixes and RewardsNote: Access to bug details and links may be kept restricted until a majority of users are updat ...