CVE-2024-0811: Inappropriate implementation in Extensions API
Chromium: CVE-2024-0811 Inappropriate implementation in Extensions API
Other sources
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-0811?
CVE-2024-0811 has been assessed as a high-severity vulnerability due to its potential impact on user security.
How do I fix CVE-2024-0811?
To resolve CVE-2024-0811, ensure that you update Microsoft Edge and Google Chrome to their latest versions.
Which products are affected by CVE-2024-0811?
CVE-2024-0811 affects Microsoft Edge (up to version 121.0.2277.83) and Google Chrome (up to version 121.0.6167.85), as well as specific versions of Fedora.
Is CVE-2024-0811 being actively exploited?
As of now, there is no public information confirming active exploitation of CVE-2024-0811, but users should still apply the necessary updates.
Where can I find more information on CVE-2024-0811?
Additional details regarding CVE-2024-0811 can be found in the security bulletins from Microsoft and Chrome release notes.