Remote Heap Corruption Vulnerability in Google Chrome Prior to 120.0.6099.224

CVE-2024-0517
8.8HIGH

Key Information

Vendor
Google
Status
Chrome
Vendor
CVE Published:
16 January 2024

Badges

😄 Trended👾 Exploit Exists📰 News Worthy

Summary

The CVE-2024-0517 vulnerability in Google Chrome allows for remote attacks to exploit heap corruption through a crafted HTML page. Although there have not been reports of exploitation by ransomware groups, Google has released an update to fix this and three other security flaws. It is essential for users to update Chrome to version 120.0.6099.224 or later to mitigate the risk. The V8 JavaScript engine, which is used in Chrome and other Chromium-based browsers, is susceptible to these vulnerabilities and requires immediate patching. Other browser technologies have also been targeted by cyber attackers, highlighting the need for organizations to implement security measures for browser use. Additionally, Microsoft Edge offers an enhanced security mode feature that can mitigate this vulnerability and protect users against exploits.

Affected Version(s)

Chrome < 120.0.6099.224

News Articles

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • Vulnerability started trending.

  • First article discovered by GBHackers on Security

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre DatabaseGoogle Feed9 News Article(s)
.