Insufficient Data Validation in Dawn for Google Chrome on Android
CVE-2024-7256

8.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 August 2024

Badges

๐Ÿ“ฐ News Worthy

What is CVE-2024-7256?

A vulnerability exists in the Dawn component of Google Chrome on Android, where insufficient data validation could allow a remote attacker to execute arbitrary code. This vulnerability is particularly concerning as it can be exploited through a specially crafted HTML page. Users of the affected versions are advised to update to the latest version, 127.0.6533.88 or above, to mitigate this security risk. The issue exemplifies the need for robust data handling practices in web browsers to prevent unauthorized access and potential system compromise.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Chrome 127.0.6533.88

News Articles

Google Chrome 127 Release Addressed Multiple Security Bugs

Google addressed one critical and two high-severity flaws with the Chrome 127 release for Desktop and Android and urged users to update.

Microsoft Edge Vulnerability Let Attackers Execute Arbitrary Code

Microsoft has released a critical security update for its Edge browser to address multiple vulnerabilities, including a severe validation flaw that could allow attackers to execute arbitrary code on affected systems.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • ๐Ÿ“ฐ

    First article discovered by CybersecurityNews

  • Vulnerability published

.