CVE-2024-9956: Inappropriate implementation in Web Authentication
Accessibility. An authentication issue was addressed with improved state management.
Other sources
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
AirPlay. An input validation issue was addressed.
— Apple
AirPlay. The issue was addressed with improved memory handling.
— Apple
ARKit. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-9954
- CVE-2024-9955
- CVE-2024-9957
- CVE-2024-9958
- CVE-2024-9959
- CVE-2024-9960
- CVE-2024-9961
- CVE-2024-9962
- CVE-2024-9963
- CVE-2024-9964
- CVE-2024-9965
- CVE-2024-9966
- CVE-2025-1930
- CVE-2025-1939
- CVE-2025-1931
- CVE-2025-1932
- CVE-2025-1933
- CVE-2025-1940
- CVE-2024-9956
- CVE-2025-1934
- CVE-2025-1941
- CVE-2025-1942
- CVE-2025-1935
- CVE-2025-1936
- CVE-2025-1937
- CVE-2025-1938
- CVE-2025-1943
- CVE-2025-24141
- CVE-2025-24126
- CVE-2025-24129
- CVE-2025-24131
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24137
- CVE-2025-24127
- CVE-2025-24160
- CVE-2025-24161
- CVE-2025-24163
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24085
- CVE-2025-24111
- CVE-2025-24086
- CVE-2025-24144
- CVE-2025-24107
- CVE-2025-24159
- CVE-2025-24117
- CVE-2025-24091
- CVE-2025-24166
- CVE-2025-24104
- CVE-2025-24128
- CVE-2025-24113
- CVE-2025-24149
- CVE-2025-24145
- CVE-2025-24154
- CVE-2025-24143
- CVE-2025-24158
- CVE-2025-24162
- CVE-2025-24150
- CVE-2025-24184
- CVE-2025-24089
- CVE-2025-24090
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-31262
- CVE-2025-31185
- CVE-2025-24189
Frequently Asked Questions
What is the severity of CVE-2024-9956?
CVE-2024-9956 has been marked as a high-severity vulnerability affecting multiple versions of browsers that utilize Chromium.
How do I fix CVE-2024-9956?
To mitigate CVE-2024-9956, users should update Google Chrome to version 130.0.6723.58 or later, or update Microsoft Edge to the latest available version.
Which versions of browsers are affected by CVE-2024-9956?
CVE-2024-9956 affects Google Chrome versions prior to 130.0.6723.58 and Microsoft Edge versions prior to 130.0.2849.46.
Is CVE-2024-9956 related to Microsoft Edge?
Yes, CVE-2024-9956 affects Microsoft Edge as it is built on the Chromium engine and inherits vulnerabilities from Chrome.
Can CVE-2024-9956 impact mobile devices?
CVE-2024-9956 primarily affects desktop versions, but ensure that mobile browsers are updated as they may also utilize the same underlying engine.