PT-2024-8725 · Google+1 · Google Chrome+1

Micky

·

Published

2024-11-12

·

Updated

2025-01-31

·

CVE-2024-11114

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 131.0.6778.69
Description The issue is related to an inappropriate implementation in Views, allowing a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This is considered a medium severity issue.
Recommendations For Google Chrome versions prior to 131.0.6778.69, update to version 131.0.6778.69 or later to mitigate the risk. As a temporary workaround, consider restricting access to potentially vulnerable HTML pages until the update is applied.

Fix

Related Identifiers

BDU:2024-10328
CVE-2024-11114
DSA-5817-1
OPENSUSE-SU-2024:0373-1
OPENSUSE-SU-2024:0374-1
OPENSUSE-SU-2024:14511-1

Affected Products

Debian
Google Chrome