First published: Mon Nov 13 2023(Updated: )
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Credit: Matan Berson @MtnBer chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <121.0.6167.85 | 121.0.6167.85 |
Google Chrome (Trace Event) | <121.0.6167.85 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-3172 has a high severity rating due to its potential for remote code execution.
To fix CVE-2024-3172, update Google Chrome to version 121.0.6167.85 or later.
An attacker can execute arbitrary code on a user's system by convincing them to engage in specific user interface gestures.
CVE-2024-3172 affects all versions of Google Chrome prior to 121.0.6167.85.
Insufficient data validation in CVE-2024-3172 refers to the vulnerability that allows crafted HTML pages to bypass security checks and execute untrusted code.