Remote Code Execution Vulnerability in Google Chrome Prior to 123.0.6312.86

CVE-2024-2887
Currently unrated 🤨

Key Information

Vendor
Google
Status
Chrome
Vendor
CVE Published:
26 March 2024

Badges

👾 Exploit Exists🔴 Public PoC📰 News Worthy

Summary

A remote code execution vulnerability, CVE-2024-2887, was discovered in Google Chrome prior to version 123.0.6312.86, which allowed a remote attacker to execute arbitrary code via a crafted HTML page. The update to Chrome version 123.0.6312.86/.87 addresses this vulnerability, along with several others, including two zero-day exploits showcased at the Pwn2Own 2024 hacking competition. The vulnerabilities include a use-after-free vulnerability in ANGLE, a cross-platform graphics engine abstraction layer, a high-severity use-after-free issue in Dawn, and two high-severity vulnerabilities involving WebCodecs and WebAssembly. These vulnerabilities revealed at Pwn2Own 2024 highlight the importance of timely updates to mitigate potential risks. Users are encouraged to update their browsers immediately to protect against these vulnerabilities.

Affected Version(s)

Chrome < 123.0.6312.86

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Timeline

  • 👾

    Exploit exists.

  • First article discovered by GBHackers on Security

  • Vulnerability Reserved.

  • Vulnerability published.

Collectors

NVD DatabaseMitre DatabaseGoogle Feed2 Proof of Concept(s)4 News Article(s)
.