CVE Published: 17/09/2024 |
CVE Updated: 18/09/2024 |
CVE Year: 2024 Source: Chrome |
Vendor: Google |
Product: Chrome Status : PUBLISHED
CVE-2024-8907 Description
Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (Chromium security severity: Medium)