CVE-2024-3172 is a high-severity vulnerability in Google Chrome's DevTools, affecting versions prior to 121.0.6167.85. It stems from insufficient data validation, allowing a remote attacker to execute arbitrary code through a crafted HTML page if a user is convinced to perform specific UI gestures. With a CVSS score of 8.8, this vulnerability presents a significant risk due to its low attack complexity and high potential for confidentiality, integrity, and availability impacts. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 121.0.6167.85CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 121.0.6167.85, < 121.0.6167.85CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.