CVE-2024-6996
Aug. 6, 2024, 4:30 p.m.
Tags
Product(s) Impacted
Google Chrome
- prior to 127.0.6533.72
Description
Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
CWE ID: 362Date
Published: Aug. 6, 2024, 4:15 p.m.
Last Modified: Aug. 6, 2024, 4:30 p.m.
Status : Undergoing Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
More infoSource
chrome-cve-admin@google.com