CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
17.3%
chromium is vulnerable to UI Spoofing. The vulnerability is due to inappropriate implementation in Autofill in Google Chrome, allowing attackers who convince users to install a malicious app can exploit this vulnerability to perform UI spoofing through a crafted app.
chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_16.html
issues.chromium.org/issues/328278717
lists.fedoraproject.org/archives/list/[email protected]/message/CWIVXXSVO5VB3NAZVFJ7CWVBN6W2735T/
lists.fedoraproject.org/archives/list/[email protected]/message/PCWPUBGTBNT4EW32YNZMRIPB3Y4R6XL6/
lists.fedoraproject.org/archives/list/[email protected]/message/WEP5NJUWMDRLDQUKU4LFDUHF5PCYAPIO/
security-tracker.debian.org/tracker/CVE-2024-3838
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
17.3%