Upstream information

CVE-2024-3841 at MITRE

Description

Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)

Upstream Security Advisories:

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

SUSE Bugzilla entry: 1222958 [IN_PROGRESS]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • chromedriver >= 124.0.6367.201-1.1
  • chromium >= 124.0.6367.201-1.1
Patchnames:
openSUSE Tumbleweed GA chromedriver-124.0.6367.201-1.1


SUSE Timeline for this CVE

CVE page created: Wed Apr 17 13:45:07 2024
CVE page last modified: Tue May 14 11:44:53 2024