First published: Mon Aug 14 2023(Updated: )
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
Credit: Derin Eryilmaz chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <120.0.6099.62 | 120.0.6099.62 |
Google Chrome (Trace Event) | <120.0.6099.62 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2024-3175 is rated as Low in terms of Chromium security.
To fix CVE-2024-3175, you should update Google Chrome to version 120.0.6099.62 or later.
CVE-2024-3175 involves a privilege escalation attack that can be executed via a crafted Chrome Extension.
CVE-2024-3175 affects Google Chrome versions prior to 120.0.6099.62.
The vendor for the product affected by CVE-2024-3175 is Google.