Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-5836

Опубликовано: 11 июн. 2024
Источник: debian
EPSS Низкий

Описание

Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromiumfixed126.0.6478.56-1package
chromiumend-of-lifebullseyepackage
chromiumend-of-lifebusterpackage

Примечания

  • https://ading.dev/blog/posts/chrome_sandbox_escape.html

EPSS

Процентиль: 72%
0.00735
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 года назад

Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 8.8
nvd
около 1 года назад

Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)

msrc
около 1 года назад

Chromium: CVE-2024-5836 Inappropriate Implementation in DevTools

CVSS3: 8.8
github
около 1 года назад

Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость набора инструментов для веб-разработки DevTools браузеров Microsoft Edge и Google Chrome, позволяющая нарушителю скомпрометировать систему

EPSS

Процентиль: 72%
0.00735
Низкий