← Back

CVE-2024-7023

nvd nist
Published: Sep 23, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)

Affected (1)

Products: Google: Chrome
1 product
Chrome
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 128.0.6537.0
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (1)

Source: chrome-cve-admin@google.com
ExploitIssue Tracking

Timeline

No history available yet.