Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
Published May 1, 2024
8.8
HIGHCVSS 3.1
EPSS 1.24%
Description
Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected products
-
- Version 124.0.6367.118StatusaffectedConstraints<124.0.6367.118
- Version
Configuration 2
- 38
- 39
- 40
-
- Version 0StatusaffectedConstraints<124.0.6367.118
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
1 other source (CISA ADP) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 4, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.24% (0.01239) | 68.03th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.23% (0.01228) | 64.85th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.96% (0.00958) | 74.41th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.80% (0.02803) | 76.85th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.96% (0.00958) | 74.89th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 12.15th | v3 (v2023.03.01) |
| Jun 11, 2024 | 0.04% (0.00044) | 10.21th | v3 (v2023.03.01) |
| May 3, 2024 | 0.04% (0.00045) | 14.33th | v3 (v2023.03.01) |
| May 2, 2024 | 0.04% (0.00043) | 8.26th | v3 (v2023.03.01) |
References (7)
- https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_30.html Release Notes
- https://issues.chromium.org/issues/335003891 ExploitIssue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L7I4FMQSOVTCIIH4XT2MJGEQRUACLPB6/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UOC3HLIZCGMIJLJ6LME5UWUUIFLXEGRN/ Mailing List
Change history (0)
No recorded changes yet.