CVE-2024-1672

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 21, 2024
Updated: Dec 19, 2024
CWE ID 474

Summary

CVE-2024-1672 is a medium severity vulnerability affecting Google Chrome versions prior to 122.0.6261.57. The issue arises from an inappropriate implementation in Content Security Policy. A remote attacker can exploit this vulnerability by crafting a malicious HTML page to bypass the content security policy, potentially leading to the execution of malicious code. This could result in information disclosure, unauthorized access, or other security risks. Users are advised to update their Chrome browsers to the latest version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share