Permissions, Privileges, and Access Controls in Google Chromium - CVE-2024-11115

 

Permissions, Privileges, and Access Controls in Google Chromium - CVE-2024-11115

Published: November 12, 2024


Vulnerability identifier: #VU100318
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11115
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient policy enforcement in Navigation in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.


Affected software

Google Chromium
Microsoft Edge
Google Chrome
Gentoo Linux
Debian Linux
Fedora
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
www-client/opera
chromium
chromium (Debian package)
www-client/microsoft-edge
www-client/chromium
www-client/google-chrome

How to mitigate CVE-2024-11115

Install update from vendor's website.

Google Chromium - update to 131.0.6778.69
Microsoft Edge - update to 131.0.2903.48
Google Chrome - update to 131.0.6778.69
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
www-client/opera - update to 119.0.5497.12
chromium - addressed in versions 131.0.6778.85-1.el8, 131.0.6778.85-1.el9, 131.0.6778.85-1.el10_0, 131.0.6778.85-1.fc39, 131.0.6778.85-1.fc40, 131.0.6778.85-1.fc41, 134.0.6998.35-1.fc42
chromium (Debian package) - update to 131.0.6778.85-1~deb12u1
www-client/microsoft-edge - update to 134.0.3124.83
www-client/chromium - update to 134.0.6998.117
www-client/google-chrome - update to 134.0.6998.117

External References

Related Security Bulletins