CVE-2024-45489General

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context. NOTE: this is a no-action cloud vulnerability with zero affected users.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-09-03)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-07: 1Mentions · 2026-09-03: 303-0709-03
Signal classification1 categories
General
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-071
General1
2026-09-033
General3
Full discourse4 posts
  • Frederick James@frederickjames
    General

    Convex is the go to if you want real time magic or have tonnes of tables, indexes, distributed compute, permissions etc in one place. It’s one of the few platforms where IaC is basically built in. Most of you won't need this! Also, Firebase references: http://arc.net/blog/CVE-2024-45489-incident-response https://digital.nhs.uk/cyber-alerts/2018/cc-2511 https://blog.gitguardian.com/misconfigurations-in-google-firebase-lead-to-over-19-8-million-leaked-secrets/

    Post summary

    The post merely cites a CVE and related hyperlinks but offers no concrete details on exploitation, patches, or technical specifics; further information likely resides in the linked resources.

    00011124.0K
    16.8K followersView on X
  • Frederick James@frederickjames
    General

    @JeremyLasne the more you look into it the worse it gets https://arc.net/blog/CVE-2024-45489-incident-response https://digital.nhs.uk/cyber-alerts/2018/cc-2511 https://blog.gitguardian.com/misconfigurations-in-google-firebase-lead-to-over-19-8-million-leaked-secrets/ it's endless

    Post summary

    The post cites a CVE and related resources, but does not provide evidence of exploitation, patches, technical details, or a PoC.

    20040326
    16.8K followersView on X
  • Frederick James@frederickjames
    General

    @Khaled_dev1m it's reductive to blame developers when there's endless examples. the architecture lends itself to vulnerabilities https://arc.net/blog/CVE-2024-45489-incident-response https://digital.nhs.uk/cyber-alerts/2018/cc-2511 https://blog.gitguardian.com/misconfigurations-in-google-firebase-lead-to-over-19-8-million-leaked-secrets/

    Post summary

    The tweet refers to a few blog posts containing CVE references but provides no concrete exploit details, patch information, or evidence of active exploitation.

    0001160
    15.9K followersView on X
  • Dami Dina@DamiDina
    General

    @FlyaKiet @diabrowser @browsercompany aren't you worried about your browser data https://arc.net/blog/CVE-2024-45489-incident-response

    Post summary

    The tweet merely links to a blog post about CVE‑2024‑45489 without providing any further technical detail, PoC, exploit code, or patch information.

    10000100
    3.0K followersView on X

Explore more