CVE-2024-6995: Inappropriate implementation in Fullscreen
Chromium: CVE-2024-6995 Inappropriate implementation in Fullscreen
Other sources
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6995?
CVE-2024-6995 is classified as a high-severity vulnerability that could potentially allow unauthorized access.
How do I fix CVE-2024-6995?
To address CVE-2024-6995, update Microsoft Edge to version 127.0.2651.74 or Google Chrome to version 127.0.6533.72 immediately.
What software is affected by CVE-2024-6995?
CVE-2024-6995 affects Microsoft Edge (Chromium-based) up to version 127.0.2651.74 and Google Chrome up to version 127.0.6533.72.
Is there a workaround for CVE-2024-6995?
There are currently no recommended workarounds for CVE-2024-6995; users should apply the available updates.
Who is responsible for fixing CVE-2024-6995?
Google and Microsoft are responsible for addressing CVE-2024-6995 through their respective browser updates.