{"id":"CGA-w4xw-9rg2-p9m8","modified":"2026-07-17T19:23:59.365003081Z","published":"2025-10-30T21:00:57Z","upstream":["CVE-2024-7971","GHSA-pq5w-h3jm-m95c"],"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7971"},{"type":"ADVISORY","url":"https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html"},{"type":"REPORT","url":"https://issues.chromium.org/issues/360700873"},{"type":"FIX","url":"https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/"}],"affected":[{"package":{"name":"chromium","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/chromium?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"128.0.6613.84-r0"}]}],"ecosystem_specific":{"components":[{"component_version":"127.0.6533.119-r1","component_type":"apk","component_location":"/.PKGINFO","component_purl":"pkg:apk/chromium@127.0.6533.119-r1","latest_event_status":"fixed","latest_event_timestamp":"2024-08-28T18:00:43Z","architecture":"aarch64","component_name":"chromium"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-w4xw-9rg2-p9m8.json"}},{"package":{"name":"chromium","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/chromium?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"128.0.6613.84-r0"}]}],"ecosystem_specific":{"components":[{"architecture":"aarch64","component_name":"chromium","component_version":"127.0.6533.119-r1","component_type":"apk","component_location":"/.PKGINFO","component_purl":"pkg:apk/chromium@127.0.6533.119-r1","latest_event_status":"fixed","latest_event_timestamp":"2024-08-28T18:00:43Z"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-w4xw-9rg2-p9m8.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}