CVE-2024-6778: 341136300 High Race in DevTools
Chromium: CVE-2024-6778 Race in DevTools
Other sources
Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 126.0.6478.182 - Upgrade
Upgrade
Chromium (Google Chrome/Edge Chromium-based DevTools)to a version that resolves this vulnerability.Fixed in 126.0.6478.182
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6778?
CVE-2024-6778 has been evaluated as a medium-severity vulnerability impacting Chromium-based browsers.
How do I fix CVE-2024-6778?
To fix CVE-2024-6778, ensure that you are using the latest version of Microsoft Edge or Google Chrome.
Which versions of Microsoft Edge are affected by CVE-2024-6778?
CVE-2024-6778 affects versions of Microsoft Edge prior to 126.0.2592.113.
Is Google Chrome affected by CVE-2024-6778?
Yes, Google Chrome versions prior to 126.0.6478.182 are affected by CVE-2024-6778.
What does CVE-2024-6778 involve?
CVE-2024-6778 involves a race condition vulnerability in DevTools within Chromium.