Sandbox Escape via GPU Process Compromise
CVE-2024-3157

9.6CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
10 April 2024

What is CVE-2024-3157?

The vulnerability presents an out of bounds memory access issue in the Compositing component of Google Chrome. This flaw impacts versions of Google Chrome before 123.0.6312.122, potentially allowing a remote attacker to exploit the GPU process. By utilizing specific UI gestures, an unauthenticated attacker could initiate a sandbox escape, which poses significant security risks to users. Timely updates and security patches are essential to mitigate the risks associated with this vulnerability.

Affected Version(s)

Chrome 123.0.6312.122

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.