CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-5836

Critical Severity|Google
77
SVRS
8.8
CVSSv3
0.00491
EPSS
Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
TAGS
In The Wild
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:RS:UC:HI:HA:H
PUBLICATION DATE2024-06-11
LAST MODIFIED2025-03-14
SOCRadarAI Insight

Description

CVE-2024-5836 is a critical vulnerability in Google Chrome that allows an attacker to execute arbitrary code on a victim's computer by convincing them to install a malicious Chrome extension. This vulnerability has a CVSS score of 8.8 and an SVRS of 86, indicating a high level of severity and urgency.

Key Insights

  • Active Exploitation: This vulnerability is actively exploited in the wild, meaning that hackers are using it to attack systems.
  • High Impact: Successful exploitation of this vulnerability could allow an attacker to take complete control of a victim's computer, including accessing sensitive data, installing malware, or launching further attacks.
  • Easy Exploitation: The vulnerability is relatively easy to exploit, requiring only that a victim be convinced to install a malicious Chrome extension.
  • Threat Actors: Specific threat actors or APT groups exploiting this vulnerability have not been identified.

Mitigation Strategies

  • Update Chrome: Install the latest version of Google Chrome (126.0.6478.54 or later) to patch this vulnerability.
  • Disable Unknown Extensions: Disable any unknown or untrusted Chrome extensions.
  • Use a Web Application Firewall (WAF): Implement a WAF to block malicious traffic targeting this vulnerability.
  • Educate Users: Educate users about the risks of installing unknown Chrome extensions and the importance of keeping their software up to date.

Additional Information

If you have any further questions regarding this incident, you can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information.

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

No IOCs found for this CVE

No exploits found for this CVE

SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

No tweets found for this CVE

Configuration 1
TypeVendorProduct
AppGooglechrome
Configuration 2
TypeVendorProduct
OSFedoraprojectfedora
ReferenceLink
AF854A3A-2127-422B-91AE-364DA2661108https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop.html
AF854A3A-2127-422B-91AE-364DA2661108https://issues.chromium.org/issues/341875171
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/7VXA32LXMNK3DSK3JBRLTBPFUH7LTODU/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/MPU7AB53QQVNTBPGRMJRY5SXJNYWW3FX/
[email protected]https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop.html
[email protected]https://issues.chromium.org/issues/341875171
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/7VXA32LXMNK3DSK3JBRLTBPFUH7LTODU/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/MPU7AB53QQVNTBPGRMJRY5SXJNYWW3FX/
[email protected]https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop.html
[email protected]https://issues.chromium.org/issues/341875171
[email protected]https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop.html
[email protected]https://issues.chromium.org/issues/341875171
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/7VXA32LXMNK3DSK3JBRLTBPFUH7LTODU/
[email protected]https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop.html
[email protected]https://issues.chromium.org/issues/341875171
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/7VXA32LXMNK3DSK3JBRLTBPFUH7LTODU/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/MPU7AB53QQVNTBPGRMJRY5SXJNYWW3FX/
CWE IDCWE NameDescription
CWE-474Use of Function with Inconsistent ImplementationsThe code uses a function that has inconsistent implementations across operating systems and versions.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.