CVE-2024-11919: Inappropriate implementation in Intents
Published Jul 11, 2024
·Updated
Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Credit
Mohit Raj (shadow2639)
Affected Software
4 affected componentsFixes available
Google Chrome<129.0.6668.58
All of the following
Google Chrome<129.0.6668.58
Google Android
Google Chrome<129.0.6668.58
129.0.6668.58
Event History
Jul 11, 2024
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Nov 14, 2025
CVE Published
via MITRE·02:29 AM
Data Sourced
via MITRE·02:29 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-11919?
The severity of CVE-2024-11919 is classified as Low by Chromium security standards.
2
How do I fix CVE-2024-11919?
To fix CVE-2024-11919, you should update Google Chrome on Android to version 129.0.6668.58 or later.
3
What can an attacker do with CVE-2024-11919?
An attacker can perform UI spoofing on affected devices via a crafted HTML page.
4
What versions of Google Chrome are affected by CVE-2024-11919?
Google Chrome versions prior to 129.0.6668.58 on Android are affected by CVE-2024-11919.
5
Is CVE-2024-11919 present in desktop versions of Google Chrome?
CVE-2024-11919 specifically affects Google Chrome on Android and does not apply to desktop versions.