Use After Free Vulnerability in Google Chrome Accessibility
CVE-2024-11113

8.8HIGH

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
12 November 2024

Summary

A use after free vulnerability in the Accessibility feature of Google Chrome prior to version 131.0.6778.69 can be exploited by a remote attacker who has compromised the renderer process. By leveraging a specially crafted HTML page, an attacker may be able to trigger heap corruption, posing significant risks to user security and data integrity.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseGoogle Feed
.