PT-2024-8724 · Google+1 · Google Chrome+1

Mastersplinter

·

Published

2024-10-07

·

Updated

2025-01-02

·

CVE-2024-11115

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome on iOS versions prior to 131.0.6778.69
Description The issue is related to insufficient policy enforcement in the Navigation component of Google Chrome on iOS. This allows a remote attacker to perform privilege escalation via a series of UI gestures. The severity of this issue is medium.
Recommendations For Google Chrome on iOS versions prior to 131.0.6778.69, update to version 131.0.6778.69 or later to resolve the issue. As a temporary workaround, consider restricting access to the Navigation component until a patch is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-10327
CVE-2024-11115
DSA-5817-1
OPENSUSE-SU-2024:0373-1
OPENSUSE-SU-2024:0374-1
OPENSUSE-SU-2024:14511-1

Affected Products

Debian
Google Chrome