PT-2024-4352 · Google · Google Chrome+1

CVE-2024-1694

·

Published

2024-03-08

·

Updated

2024-12-26

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Updator versions prior to 1.3.36.351
Description The issue is related to inadequate access control in the Google Updator program, allowing an attacker to bypass discretionary access control using a specially crafted file. This could enable a local attacker to exploit the weakness, potentially gaining elevated privileges on a system with Google Chrome installed.
Recommendations For versions prior to 1.3.36.351, update to version 1.3.36.351 or later to resolve the issue. As a temporary workaround, consider restricting access to the Google Updator until a patch is applied.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04841
CVE-2024-1694

Affected Products

Google Chrome
Google Updator