Medium severity4.3NVD Advisory· Published Jan 24, 2024· Updated Jun 17, 2026
CVE-2024-0811
CVE-2024-0811
Description
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_23.htmlnvdRelease NotesVendor Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/MMI6GXFONZV6HE3BPZO3AP6GUVQLG4JQ/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/VXDSGAFQD4BDB4IB2O4ZUSHC3JCVQEKC/nvdMailing ListThird Party Advisory
- crbug.com/1494490nvdPermissions Required
- packetstormsecurity.com/files/177172/Chrome-chrome.pageCapture.saveAsMHTML-Extension-API-Blocked-Origin-Bypass.htmlnvd
News mentions
0No linked articles in our index yet.