CVE-2024-9966: LOW Inappropriate implementation in Navigations.
Chromium: CVE-2024-9966 Inappropriate implementation in Navigations
Other sources
Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9966?
CVE-2024-9966 has a severity rating that indicates a potential significant impact on affected systems.
How do I fix CVE-2024-9966?
To fix CVE-2024-9966, users should update Google Chrome or Microsoft Edge (Chromium-based) to the latest version.
Which versions are affected by CVE-2024-9966?
CVE-2024-9966 affects Google Chrome versions prior to 130.0.6723.58 and Microsoft Edge versions prior to 130.0.2849.46.
What is the nature of the vulnerability in CVE-2024-9966?
CVE-2024-9966 involves inappropriate handling of specific data within the affected browsers.
What types of software are impacted by CVE-2024-9966?
CVE-2024-9966 impacts both Google Chrome and Chromium-based Microsoft Edge browsers.