Permissions, Privileges, and Access Controls in Google Chromium - CVE-2024-0804
Published: January 23, 2024 / Updated: January 23, 2024
Google Chromium
Microsoft Edge
Google Chrome
Debian Linux
Gentoo Linux
Fedora
dev-qt/qtwebengine
www-client/microsoft-edge
chromium
chromium (Debian package)
www-client/chromium
www-client/google-chrome
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient policy enforcement in iOS Security UI in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.