HIGH
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page
Published Mar 26, 2024
8.1
HIGHCVSS 3.1
EPSS 17.92%
Description
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Affected products
-
Affected
- ≥ 123.0.6312.86, < 123.0.6312.86
Configuration 2
OR
- 38
- 39
- 40
-
Affected
- ≥ 0, < 123.0.6312.86
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_26.html Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27831 Advisory
- https://issues.chromium.org/issues/330588502 ExploitIssue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3YUWGSMA5X2NQP5XEFCLRWNX6246GZ2C/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G3RKI7VTQSIAI3PVZGRCHOSELTQXQ5FQ/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IQMRHKDEG4J7TMRRRGUGW6GS4MVBX5IT/ Mailing List
- https://www.zerodayinitiative.com/blog/2024/5/2/cve-2024-2887-a-pwn2own-winning-bug-in-google-chrome exploitThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Mar 26, 2024
Updated Mar 28, 2025
Reserved Mar 26, 2024
Link CVE-2024-2887
CISA Vulnrichment
Updated May 4, 2024
Red Hat
No data
GitHub
No data