CVE-2024-9956

Published Oct 15, 2024

Last updated a month ago

Overview

Description
Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Source
chrome-cve-admin@google.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    2 Apr 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    31 Mar 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    30 Mar 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Androidda jiddiy zaiflik! Qarshi oling: CVE-2024-9956, bu Android Chrome’idagi jiddiy zaiflik bo‘lib, u Bluetooth orqali PassKeyni o'g'irlash imkonini beradi. Asosiy himoya strategiyalarini o‘rganib oling. Batafsil: https://t.co/cFKKv1NvpK https://t.co/EYGghvE043

    @haad_uz

    29 Mar 2025

    74 Impressions

    3 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-9956: Critical #WebAuthentication_Vulnerability in #Google_Chrome on #Android https://t.co/vf54X6kZyN https://t.co/o71IQEjRe0

    @omvapt

    29 Mar 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    29 Mar 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    27 Mar 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. CVE-2024-9956: Critical WebAuthentication Vulnerability in Google Chrome on Android https://t.co/xmQZeWBUQP

    @itsecuritynewsl

    26 Mar 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    23 Mar 2025

    21 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. CVE-2024-9956 - PassKey Account Takeover in All Mobile Browsers https://t.co/kMVGxnBzZm https://t.co/P7FsBIt7tm

    @secharvesterx

    22 Mar 2025

    31 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    22 Mar 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2024-9956 - PassKey Account Takeover in All Mobile Browsers Attack combines 2D barcodes (QR) and Bluetooth interception, allowing you to phishing passkeys. https://t.co/rTxP5nG8YK

    @_mattata

    20 Mar 2025

    3702 Impressions

    16 Retweets

    52 Likes

    18 Bookmarks

    2 Replies

    0 Quotes

  13. CVE-2024-9956 – PassKey Account Takeover in All Mobile Browsers https://t.co/O2tRLcLQuT 17

    @cevaboyz

    19 Mar 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    18 Mar 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. #WebApp_Security #Offensive_security 1. Disclosing YouTube Creator Emails https://t.co/D9isBiHKGg 2. PassKey Account Takeover in All Mobile Browsers (CVE-2024-9956) https://t.co/5Dpjr8hojK ]-> Cross Device Authentication Tesing Tool

    @ksg93rd

    18 Mar 2025

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    17 Mar 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    16 Mar 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. Actively exploited CVE : CVE-2024-9956

    @transilienceai

    15 Mar 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  19. Finally releasing my security research about phishing PassKeys from mobile browsers! CVE-2024-9956. Check it out, re-tweet and let me know what you think! https://t.co/Q6PIT6RKE2 #security #bugbounty

    @m4st3rspl1nt3r

    24 Feb 2025

    88 Impressions

    1 Retweet

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations