HIGH
Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
Published Mar 26, 2024
8.8
HIGHCVSS 3.1
EPSS 3.37%
Description
Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Affected products
-
- Version 123.0.6312.86StatusaffectedConstraints<123.0.6312.86
- Version
Configuration 2
OR
- 38
- 39
- 40
-
- Version 40StatusaffectedConstraints<1.fc40
- Version
-
- Version 0StatusaffectedConstraints<123.0.6312.86
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Fedora Project | Fedora | n/a |
| ||||||
| Chrome | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_26.html Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27827 Advisory
- https://issues.chromium.org/issues/327807820 ExploitIssue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3YUWGSMA5X2NQP5XEFCLRWNX6246GZ2C/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G3RKI7VTQSIAI3PVZGRCHOSELTQXQ5FQ/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IQMRHKDEG4J7TMRRRGUGW6GS4MVBX5IT/ Mailing List
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Mar 26, 2024
Updated Mar 14, 2025
Reserved Mar 26, 2024
Link CVE-2024-2883
CISA Vulnrichment
Updated Mar 14, 2025
ENISA EUVD
EUVD-2024-27827 Assigner Chrome
Published Mar 26, 2024
Updated Mar 14, 2025
Exploited since n/a
Link EUVD-2024-27827