CVE-2024-0805 describes an inappropriate implementation vulnerability in the Downloads feature of Google Chrome, affecting versions prior to 121.0.6167.85, as well as Fedora Project's Chrome and Fedora. This flaw allows a remote attacker to conduct domain spoofing through a specially crafted domain name. The vulnerability is rated Medium severity with a CVSS score of 4.3, indicating a low impact on integrity (I:L) and requiring user interaction (UI:R) for exploitation. While the attack vector is network-based (AV:N) and complexity is low (AC:L), the primary risk is limited to misleading users through spoofed domain names. Currently, there is no evidence of active exploitation, nor are there any public exploit modules or proof-of-concept code available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, suggesting low public awareness and a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 121.0.6167.85, < 121.0.6167.85CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 121.0.6167.85CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.