Skip to main content
CVE Vulnerability Database

CVE-2024-0810: Google Chrome DevTools Information Disclosure

CVE-2024-0810 is an information disclosure vulnerability in Google Chrome DevTools that allows malicious extensions to leak cross-origin data. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2024-0810 Overview

CVE-2024-0810 is an insufficient policy enforcement vulnerability in the DevTools component of Google Chrome prior to version 121.0.6167.85. An attacker who convinces a user to install a malicious extension can leak cross-origin data through a crafted Chrome Extension. Google classifies the Chromium security severity as Medium, and the issue is tracked under Chromium bug #1496250. The flaw is categorized under [CWE-284] Improper Access Control.

Critical Impact

Successful exploitation allows a malicious Chrome Extension to bypass DevTools policy controls and read data from cross-origin resources, leading to confidentiality loss for browsing sessions.

Affected Products

  • Google Chrome versions prior to 121.0.6167.85 (Desktop stable channel)
  • Fedora Linux packages of Google Chrome tracked in the referenced Fedora package announcements
  • Chromium-based browsers that had not merged the upstream fix at the time of release

Discovery Timeline

  • 2024-01-23 - Google publishes the Stable Channel Update for Desktop referencing this fix (Chrome Releases)
  • 2024-01-24 - CVE-2024-0810 published to NVD
  • 2026-06-17 - Last updated in the NVD database

Technical Details for CVE-2024-0810

Vulnerability Analysis

The defect resides in Chrome DevTools, the built-in developer tooling exposed through the chrome://devtools and devtools:// protocol handlers. DevTools normally enforces same-origin and extension policy boundaries when scripts, network data, or storage are inspected. In affected versions those policy checks were insufficient, allowing an installed extension to invoke DevTools-mediated behavior against resources belonging to a different origin.

Exploitation requires user interaction: the victim must be persuaded to install a malicious extension from a third-party source or sideload it in developer mode. Once the extension is loaded, it can craft requests or DevTools interactions that read cross-origin responses that the Same-Origin Policy would otherwise block. The impact is limited to confidentiality; integrity and availability are not affected.

Root Cause

The root cause is improper access control [CWE-284] in DevTools policy enforcement. DevTools code paths reachable from an extension context did not validate the requesting origin strictly enough before returning data associated with other origins. Google's Chromium bug tracker entry #1496250 contains the restricted technical detail.

Attack Vector

The attack vector is network-based but gated by user interaction. An attacker publishes or distributes a malicious extension, convinces the victim to install it, and then uses the extension's privileges combined with the DevTools weakness to exfiltrate cross-origin data such as authenticated responses from web applications the victim is signed into.

No public proof-of-concept has been published and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS probability reflects a low likelihood of observed exploitation. See the Chromium bug report referenced above for technical details maintained by the Chrome security team.

Detection Methods for CVE-2024-0810

Indicators of Compromise

  • Installation of Chrome extensions from outside the Chrome Web Store, particularly with permissions such as debugger, tabs, webRequest, or broad host access
  • Unexpected devtools:// or chrome-extension:// traffic patterns generated by background service workers
  • Extension manifests declaring devtools_page from unverified publishers

Detection Strategies

  • Inventory installed extensions per endpoint and correlate extension IDs against an approved allowlist
  • Inspect enterprise Chrome telemetry (ExtensionInstallReport, managed policy logs) for sideloaded or developer-mode extensions
  • Hunt for outbound requests originating from browser processes that carry cross-origin session cookies or tokens shortly after new extension installs

Monitoring Recommendations

  • Enable Chrome Enterprise reporting to forward extension install and update events to the SIEM
  • Alert on Chrome versions below 121.0.6167.85 reported by endpoint inventory
  • Review browser process child activity for anomalous network beaconing following extension changes

How to Mitigate CVE-2024-0810

Immediate Actions Required

  • Update Google Chrome to 121.0.6167.85 or later on all Windows, macOS, and Linux endpoints
  • Update Fedora Chrome packages using the Fedora advisories linked in the references
  • Audit installed extensions and remove any that are unsigned, sideloaded, or unnecessary

Patch Information

Google addressed the issue in Chrome Stable 121.0.6167.85 for Desktop, announced in the Chrome Releases Stable Channel Update. Fedora shipped corresponding package updates documented in the Fedora package announcement and a follow-up Fedora announcement. Chromium-based browsers should confirm they merged the upstream fix tied to Chromium bug #1496250.

Workarounds

  • Restrict extension installation to a managed allowlist using the ExtensionInstallAllowlist and ExtensionInstallBlocklist enterprise policies
  • Disable developer mode extensions with DeveloperToolsAvailability set to block untrusted contexts
  • Educate users to avoid installing extensions from unverified sources until patching is complete
bash
# Configuration example: Chrome enterprise policy to restrict extensions (Linux managed policy JSON)
{
  "ExtensionInstallBlocklist": ["*"],
  "ExtensionInstallAllowlist": [
    "<approved-extension-id-1>",
    "<approved-extension-id-2>"
  ],
  "DeveloperToolsAvailability": 2,
  "ExtensionInstallSources": ["https://chrome.google.com/webstore/*"]
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.