CVE-2024-6995
https://notcve.org/view.php?id=CVE-2024-6995
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html https://issues.chromium.org/issues/343938078 • CWE-358: Improperly Implemented Security Check for Standard •
CVE-2024-6990
https://notcve.org/view.php?id=CVE-2024-6990
Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_30.html https://issues.chromium.org/issues/353034820 • CWE-457: Use of Uninitialized Variable •
CVE-2024-6996
https://notcve.org/view.php?id=CVE-2024-6996
Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html https://issues.chromium.org/issues/333708039 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2024-7000
https://notcve.org/view.php?id=CVE-2024-7000
Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html https://issues.chromium.org/issues/339877158 • CWE-416: Use After Free •
CVE-2024-6998
https://notcve.org/view.php?id=CVE-2024-6998
Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html https://issues.chromium.org/issues/340098902 • CWE-416: Use After Free •