CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-0814

Medium Severity
Google
SVRS
30/100

CVSSv3
6.5/10

EPSS
0.00098/1

CVE-2024-0814 affects Google Chrome, allowing attackers to spoof the security UI. This vulnerability stems from incorrect security UI handling in the Payments feature within Google Chrome versions prior to 121.0.6167.85. A remote attacker could exploit this weakness by crafting a malicious HTML page, potentially deceiving users. The risk associated is that attackers can trick users into unknowingly providing sensitive payment information. Although the CVSS score is 6.5, indicating medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a lower immediate threat level compared to critical vulnerabilities. This means while the issue needs addressing, it's not as urgent as vulnerabilities with an SVRS above 80. However, organizations should still patch to prevent potential exploitation and maintain user trust.

No tags available
CVSS:3.1
AV:N
AC:L
PR:N
UI:R
S:U
C:N
I:H
A:N
2024-01-24

2024-01-29

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

No tweets found for this CVE

Affected Software

Configuration 1
TypeVendorProduct
AppGooglechrome
Configuration 2
TypeVendorProduct
OSFedoraprojectfedora

References

ReferenceLink
[email protected]https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_23.html
[email protected]https://crbug.com/1463935
[email protected]https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_23.html
[email protected]https://crbug.com/1463935
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/MMI6GXFONZV6HE3BPZO3AP6GUVQLG4JQ/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/VXDSGAFQD4BDB4IB2O4ZUSHC3JCVQEKC/

CWE Details

CWE IDCWE NameDescription
CWE-346Origin Validation ErrorThe software does not properly verify that the source of data or communication is valid.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence