PT-2023-9435 · Google+3 · Google Chrome+3

CVE-2024-7020

·

Publicado

2023-11-01

·

Atualizado

2025-01-02

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 124.0.6367.60
Description The issue is related to the Autofill feature in Google Chrome, where an inappropriate implementation allows a remote attacker to perform UI spoofing via a crafted HTML page. This can lead to the attacker manipulating the user interface, potentially deceiving users into taking unintended actions.
Recommendations For Google Chrome versions prior to 124.0.6367.60, update to version 124.0.6367.60 or later to resolve the issue. As a temporary workaround, consider disabling the Autofill feature until a patch is available. Restrict access to potentially vulnerable HTML pages to minimize the risk of exploitation.

Exploit

Correção

Clickjacking

UI Misrepresentation of Critical Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-07568
CVE-2024-7020
DSA-5668-1

Produtos afetados

Astra Linux
Debian
Google Chrome
Red Os