CVE-2024-8907: Insufficient data validation in Omnibox
Chromium: CVE-2024-8907 Insufficient data validation in Omnibox
Other sources
Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8907?
CVE-2024-8907 has been classified with varying severity levels, depending on the specific attack scenario and environment.
How do I fix CVE-2024-8907?
To mitigate CVE-2024-8907, ensure you update Google Chrome to version 129.0.6668.58 or later, or update Microsoft Edge as per the vendor's instructions.
Which software is affected by CVE-2024-8907?
CVE-2024-8907 affects Google Chrome versions prior to 129.0.6668.58 and certain versions of Microsoft Edge that are Chromium-based.
Is there a workaround for CVE-2024-8907?
Currently, the recommended approach is to update to the latest version of the affected browsers to address CVE-2024-8907.
When was CVE-2024-8907 disclosed?
CVE-2024-8907 was disclosed as part of the ongoing security updates for Chromium-based browsers.