CVE-2024-11116
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 79
Summary
CVE-2024-11116 is a medium severity vulnerability affecting Google Chrome up to version 131.0.6778.69. This issue arises from an inappropriate implementation in Blink, the browser engine used by Chrome. A remote attacker can exploit this flaw by convincing a user to perform specific UI gestures, enabling the adversary to carry out UI spoofing via a meticulously crafted HTML page. This vulnerability could potentially mislead users into revealing sensitive information or performing unintended actions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.