CVE-2024-7004: Insufficient validation of untrusted input in Safe Browsing
Chromium: CVE-2024-7004 Insufficient validation of untrusted input in Safe Browsing
Other sources
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-7004?
CVE-2024-7004 has not been assigned a specific severity level, but it involves insufficient validation that could lead to potential security vulnerabilities.
How do I fix CVE-2024-7004?
To fix CVE-2024-7004, update your Microsoft Edge to a version above 127.0.2651.74 or Google Chrome to version 127.0.6533.72 or higher.
What vulnerabilities does CVE-2024-7004 address in Microsoft Edge?
CVE-2024-7004 addresses vulnerabilities related to insufficient validation in Microsoft Edge due to its reliance on Chromium.
Is CVE-2024-7004 applicable to all versions of Chrome?
No, CVE-2024-7004 only affects versions of Google Chrome up to but not including 127.0.6533.72.
Which software is affected by CVE-2024-7004?
CVE-2024-7004 affects Microsoft Edge (Chromium-based) versions up to 127.0.2651.74 and Google Chrome versions up to 127.0.6533.72.