PT-2024-6550 · Google+3 · Google Chrome+3
Vulnnoob
·
Published
2024-08-21
·
Updated
2025-07-02
·
CVE-2024-7979
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Google Chrome versions prior to 128.0.6613.84
Microsoft Edge (affected versions not specified)
Description:
The issue is related to insufficient data validation in the installer, which can be exploited by a local attacker to perform privilege escalation via a crafted symbolic link. This can be achieved with a specially crafted link.
Recommendations:
For Google Chrome versions prior to 128.0.6613.84, update to version 128.0.6613.84 or later to resolve the issue.
For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Google Chrome
Edge