Heap Corruption Vulnerability in Autofill Could Lead to Remote Code Execution
CVE-2024-8639

8.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
11 September 2024

What is CVE-2024-8639?

A vulnerability in the Autofill functionality of Google Chrome for Android has been identified, allowing for potential exploitation through a crafted HTML page. This issue arises from a misuse of memory after it has been freed, which can lead to heap corruption. Malicious actors could leverage this vulnerability to perform remote code execution or manipulate user data in unintended ways. Users of Google Chrome on Android are advised to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Chrome 128.0.6613.137

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.