
Cloud Vulnerability DB
A community-led vulnerabilities database
A security vulnerability identified as CVE-2024-6995 affects Google Chrome on Android versions prior to 127.0.6533.72. The vulnerability stems from an inappropriate implementation in the Fullscreen feature that could allow a remote attacker to spoof the contents of the Omnibox (URL bar) through a crafted HTML page, provided they can convince a user to engage in specific UI gestures (Chrome Release, NVD).
The vulnerability has been assigned a CVSS v3.1 Base Score of 4.7 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N. The issue was discovered by Alesandro Ortiz and reported on 2024-06-01, for which a bounty of $6,000 was awarded (Chrome Release, NVD).
The vulnerability allows attackers to spoof the contents of the Omnibox (URL bar), which could potentially mislead users about the website they are visiting. This could lead to phishing attacks or other forms of user deception (NVD).
The vulnerability requires user interaction and specific UI gestures to be exploited. An attacker needs to craft a malicious HTML page and convince a user to interact with it in a specific way to successfully exploit the vulnerability (NVD).
The vulnerability has been patched in Google Chrome version 127.0.6533.72 for Android. Users are advised to update their browsers to this version or later to protect against this security issue (Chrome Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."