Improperly implemented security check for standard in Google Chromium - CVE-2024-1672

 

Improperly implemented security check for standard in Google Chromium - CVE-2024-1672

Published: February 20, 2024 / Updated: February 21, 2024


Vulnerability identifier: #VU86663
CSH Severity: High
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-1672
CWE-ID: CWE-358
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to incorrect implementation in Content Security Policy in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


Affected software

Google Chromium
Microsoft Edge
Google Chrome
Gentoo Linux
Debian Linux
Fedora
Chrome OS
www-client/opera
www-client/microsoft-edge
chromium
chromium (Debian package)
www-client/google-chrome
ww-client/microsoft-edge
www-client/chromium

How to mitigate CVE-2024-1672

Install update from vendor's website.

Google Chromium - update to 122.0.6261.57
Microsoft Edge - update to 122.0.2365.52
Google Chrome - update to 122.0.6261.57
www-client/opera - update to 73.0.3856.284
www-client/microsoft-edge - update to 110.0.5130.35
Chrome OS - update to 120.0.6099.302
chromium - addressed in versions 122.0.6261.57-1.fc38, 122.0.6261.57-1.fc39, 122.0.6261.69-1.el7, 122.0.6261.69-1.el8, 122.0.6261.69-1.el9, 122.0.6261.94-1.el7, 122.0.6261.94-1.el9
chromium (Debian package) - update to 122.0.6261.57-1~deb12u1
www-client/google-chrome - update to 124.0.2478.97
ww-client/microsoft-edge - update to 124.0.6367.155
www-client/chromium - update to 124.0.6367.155

External References

Related Security Bulletins