PT-2024-4232 · Google+5 · Google Chrome+5

Matt Howard

·

Published

2024-06-11

·

Updated

2025-03-19

·

CVE-2024-5840

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 126.0.6478.54
Description The issue is related to a policy bypass in the CORS mechanism, which can be exploited by a remote attacker to bypass discretionary access control. This can be achieved through a crafted HTML page, potentially allowing the attacker to disclose protected information. The severity of this issue is medium, according to Chromium's security severity rating.
Recommendations For Google Chrome versions prior to 126.0.6478.54, update to version 126.0.6478.54 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and avoiding the use of potentially vulnerable HTML pages until the update is applied.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10294
ALT-PU-2024-14830
ALT-PU-2024-9446
ALT-PU-2025-4366
BDU:2024-04718
CVE-2024-5840
DSA-5710-1
MGASA-2024-0230
OPENSUSE-SU-2024:0204-1
OPENSUSE-SU-2024:0205-1
OPENSUSE-SU-2024:0223-1
OPENSUSE-SU-2024:14122-1
OPENSUSE-SU-2024_0205-1
OPENSUSE-SU-2024_0223-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
Suse