HIGH
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
Published Jun 24, 2024
8.8
HIGHCVSS 3.1
EPSS 0.61%
Description
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected products
-
Affected
- ≥ 126.0.6478.126, < 126.0.6478.126
Configuration 1
Configuration 2
OR
- 39
- 40
-
Affected
- ≥ 0, < 126.0.6478.126
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop_24.html Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47411 Advisory
- https://issues.chromium.org/issues/345993680 ExploitIssue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6OJ65HWXYSYMH55VDO6N36EOZFUNL4O/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHV5WTU27YOIBIM2CON42SHWY6J2HPRS/ Mailing List
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Jun 24, 2024
Updated Feb 13, 2025
Reserved Jun 24, 2024
Link CVE-2024-6293
CISA Vulnrichment
Updated Jun 26, 2024
Red Hat
No data
GitHub
No data