CVE-2024-7004 describes a low-severity vulnerability in Google Chrome versions prior to 127.0.6533.72, where insufficient input validation in Safe Browsing could allow a remote attacker to bypass discretionary access controls. This bypass requires user interaction, specifically engaging in certain UI gestures with a malicious file. The CVSS score is 4.3 (Medium), indicating a network-based attack with low complexity but requiring user interaction, leading to a potential low impact on integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 127.0.6533.72CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 127.0.6533.72, < 127.0.6533.72CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.