CVE-2024-5836: Inappropriate Implementation in DevTools
Chromium: CVE-2024-5836 Inappropriate Implementation in DevTools
Other sources
Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 126.0.6478.54 - Upgrade
Upgrade
chromium/google-chrome-devtoolsto a version that resolves this vulnerability.Fixed in 126.0.6478.54
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5836?
CVE-2024-5836 has been classified as a high-severity vulnerability.
How do I fix CVE-2024-5836?
To fix CVE-2024-5836, update Google Chrome to version 126.0.6478.54 or later, or update Microsoft Edge (Chromium-based) to the latest version.
What software is affected by CVE-2024-5836?
CVE-2024-5836 affects Google Chrome versions prior to 126.0.6478.54 and Microsoft Edge (Chromium-based) that incorporates the affected Chromium engine.
Is CVE-2024-5836 being actively exploited?
There are no publicly disclosed reports of active exploitation of CVE-2024-5836 at this time.
Where can I find more information about CVE-2024-5836?
More information about CVE-2024-5836 can be found in the official release notes from Google and Microsoft regarding their respective browsers.