CVE-2024-7965

Description

An inappropriate implementation vulnerability was found in the Chromium web browser. This flaw allows an unauthenticated, remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Statement

Chromium is not shipped in any supported Red Hat offerings.

Mitigation

Until updated packages are released for Fedora and EPEL, consider temporarily swapping to an alternative web browser such as Firefox or severely restricting activity to sites you know well and trust.

Understanding the Weakness (CWE)

Other

Technical Impact: Reduce Maintainability; Increase Analytical Complexity

This issue makes it more difficult to maintain the product due to inconsistencies, which indirectly affects security by making it more difficult or time-consuming to find and/or fix vulnerabilities. It also might make it easier to introduce vulnerabilities.

Frequently Asked Questions

Want to get errata notifications? Sign up here.