CVE-2024-9958: MEDIUM Inappropriate implementation in PictureInPicture.
Chromium: CVE-2024-9958 Inappropriate implementation in PictureInPicture
Other sources
Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9958?
CVE-2024-9958 has been classified with a severity rating that indicates a potential risk to users of affected applications.
How do I fix CVE-2024-9958?
To mitigate CVE-2024-9958, update your Google Chrome to version 130.0.6723.58 or higher, or update Microsoft Edge to version 130.0.2849.46 or higher.
Which software is affected by CVE-2024-9958?
CVE-2024-9958 affects Google Chrome versions prior to 130.0.6723.58 and Microsoft Edge (Chromium-based) versions prior to 130.0.2849.46.
Is CVE-2024-9958 a zero-day vulnerability?
CVE-2024-9958 was publicly disclosed, which indicates it may be actively exploited, but specifics about its zero-day status depend on the current threat landscape.
What type of vulnerability is CVE-2024-9958?
CVE-2024-9958 is categorized as an inappropriate input validation vulnerability that could lead to various security issues.