CVE-2024-3847: Insufficient policy enforcement in WebUI
Chromium: CVE-2024-3847 Insufficient policy enforcement in WebUI
Other sources
Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-3847?
CVE-2024-3847 has been classified with a medium severity level due to insufficient policy enforcement.
How do I fix CVE-2024-3847?
To resolve CVE-2024-3847, users should update their Google Chrome or Microsoft Edge (Chromium-based) to version 124.0.6367.60 or later.
Which products are affected by CVE-2024-3847?
CVE-2024-3847 affects Google Chrome versions up to 124.0.6367.60 and Microsoft Edge Chromium-based browsers.
Is CVE-2024-3847 patched in newer versions?
Yes, CVE-2024-3847 is patched in the latest versions of Google Chrome and Microsoft Edge based on Chromium.
What platforms are impacted by CVE-2024-3847?
CVE-2024-3847 impacts multiple platforms, including Fedora versions 38, 39, and 40 that use Chromium-based browsers.