PT-2024-6550 · Google+3 · Google Chrome+3

Vulnnoob

·

Published

2024-08-21

·

Updated

2025-07-02

·

CVE-2024-7979

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Google Chrome versions prior to 128.0.6613.84 Microsoft Edge (affected versions not specified)
Description: The issue is related to insufficient data validation in the installer, which can be exploited by a local attacker to perform privilege escalation via a crafted symbolic link. This can be achieved with a specially crafted link.
Recommendations: For Google Chrome versions prior to 128.0.6613.84, update to version 128.0.6613.84 or later to resolve the issue. For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17740
ALT-PU-2025-2945
ALT-PU-2025-4366
ALT-PU-2025-7539
ALT-PU-2025-8547
BDU:2024-07694
CVE-2024-7979
DSA-5757-1
MGASA-2024-0321
OPENSUSE-SU-2024:0258-1
OPENSUSE-SU-2024:0258-2
OPENSUSE-SU-2024:14285-1

Affected Products

Alt Linux
Debian
Google Chrome
Edge