Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-36472

Published: 28 May 2024

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.

Notes

Author Note
mdeslaur
See 3408 MR, ideally in Ubuntu we would switch to disabling
the portal helper and use the user's default browser instead of
using the embedded gtkwebkit browser to improve security.
Need to test properly and make sure this works with our default
browsers.

Priority

Medium