First published: Sun Oct 29 2023(Updated: )
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Credit: NorthSea chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <120.0.6099.62 | 120.0.6099.62 |
Google Chrome (Trace Event) | <120.0.6099.62 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2024-3173 is classified as High.
To fix CVE-2024-3173, update Google Chrome to version 120.0.6099.62 or later.
CVE-2024-3173 is an insufficient data validation vulnerability in the Updater component of Google Chrome.
An attacker exploiting CVE-2024-3173 can perform OS-level privilege escalation via a malicious file.
Versions of Google Chrome prior to 120.0.6099.62 are affected by CVE-2024-3173.