CVE-2024-8906
- EPSS 0.14%
- Published 17.09.2024 21:15:13
- Last modified 25.03.2025 17:16:14
Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2024-8907
- EPSS 0.17%
- Published 17.09.2024 21:15:13
- Last modified 15.07.2025 18:23:28
Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (C...
CVE-2024-8908
- EPSS 0.09%
- Published 17.09.2024 21:15:13
- Last modified 20.03.2025 21:15:22
Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2024-8909
- EPSS 0.1%
- Published 17.09.2024 21:15:13
- Last modified 17.03.2025 16:15:23
Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2024-8904
- EPSS 0.17%
- Published 17.09.2024 21:15:12
- Last modified 02.01.2025 17:34:12
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-8638
- EPSS 0.15%
- Published 11.09.2024 14:15:14
- Last modified 13.09.2024 14:35:10
Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-8639
- EPSS 0.21%
- Published 11.09.2024 14:15:14
- Last modified 13.09.2024 14:35:11
Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-8636
- EPSS 0.2%
- Published 11.09.2024 14:15:13
- Last modified 13.09.2024 14:35:08
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-8637
- EPSS 0.15%
- Published 11.09.2024 14:15:13
- Last modified 13.09.2024 14:35:09
Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-7970
- EPSS 0.15%
- Published 03.09.2024 23:15:23
- Last modified 02.01.2025 17:40:45
Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)