First published: Mon Sep 30 2024(Updated: )
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2024%C2%A0">Google Chrome Releases</a> for more information.</p>
Credit: mastersplinter chrome-cve-admin@google.com @RenwaX23 Michael DePlante @izobashi Trend Micro Zero Day InitiativeKirin @Pwnrin an anonymous researcher Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabJohan Carlsson (joaxcar) DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n pattern-f @pattern_F_ Michael (Biscuit) Thomas @social.lol) @biscuit Hichem Maloufi Hakim Boukhadra Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeCVE-2025-24085 Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityGoogle Threat Analysis Group Uri Katz (Oligo Security) Abhay Kailasia @abhay_kailasia C
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <18.3 | 18.3 |
Apple iOS, iPadOS, and watchOS | <18.3 | 18.3 |
Microsoft Edge | ||
Microsoft Edge Beta | <130.0.2849.46 | |
Google Chrome (Trace Event) | <130.0.6723.58 | 130.0.6723.58 |
All of | ||
Google Chrome (Trace Event) | <130.0.6723.58 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-9956 has been marked as a high-severity vulnerability affecting multiple versions of browsers that utilize Chromium.
To mitigate CVE-2024-9956, users should update Google Chrome to version 130.0.6723.58 or later, or update Microsoft Edge to the latest available version.
CVE-2024-9956 affects Google Chrome versions prior to 130.0.6723.58 and Microsoft Edge versions prior to 130.0.2849.46.
Yes, CVE-2024-9956 affects Microsoft Edge as it is built on the Chromium engine and inherits vulnerabilities from Chrome.
CVE-2024-9956 primarily affects desktop versions, but ensure that mobile browsers are updated as they may also utilize the same underlying engine.