Remote Code Execution in JavaScript Boosts via Misconfigured Firebase ACLs
CVE-2024-45489

9.8CRITICAL

Key Information:

Vendor
CVE Published:
20 September 2024

Badges

👾 Exploit Exists📰 News Worthy

What is CVE-2024-45489?

The vulnerability CVE-2024-45489 allows for remote code execution in JavaScript boosts in the Arc browser due to misconfigured Firebase ACLs. This flaw had the potential to allow unauthorized individuals to run arbitrary JavaScript on users' browsers, but the vulnerability was not exploited, aside from the security researcher who reported it. The Browser Company swiftly addressed the issue, implementing security enhancements and mitigation measures to prevent future similar vulnerabilities. The Company also plans to transition away from Firebase for new features to reduce the risk of future ACL-related vulnerabilities. No action is required from Arc browser users, as the vulnerability has been fully addressed.

News Articles

Arc browser launches bug bounty program after fixing RCE bug

The Browser Company has introduced an Arc Bug Bounty Program to encourage security researchers to report vulnerabilities to the project and receive rewards.

Arc Browser Vulnerability CVE-2024-45489: Details And Response

The Browser Company addressed the Arc browser vulnerability, ensuring user safety and implementing future security enhancements.

Researcher reveals ‘catastrophic’ security flaw in the Arc browser

CVE-2024-45489 was patched in late August but would have allowed attackers to upload arbitrary code to victims with just a user ID.

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Verge

  • Vulnerability published

.