CVE-2024-3840: Insufficient policy enforcement in Site Isolation
Chromium: CVE-2024-3840 Insufficient policy enforcement in Site Isolation
Other sources
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-3840?
CVE-2024-3840 has been characterized as a vulnerability with potentially significant impact depending on its exploitation.
How do I fix CVE-2024-3840?
To address CVE-2024-3840, users should update their browsers to at least Chrome version 124.0.6367.60 or the latest version of Microsoft Edge.
Which versions of software are affected by CVE-2024-3840?
CVE-2024-3840 affects Microsoft Edge (Chromium-based) and Google Chrome up to version 124.0.6367.60, along with Fedora versions 38, 39, and 40.
What type of vulnerability is CVE-2024-3840?
CVE-2024-3840 is classified as an 'insufficient policy enforcement' vulnerability.
Is there a specific vendor remedy for CVE-2024-3840?
Yes, Microsoft recommends updating Microsoft Edge to the latest version to mitigate CVE-2024-3840.