Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-7000

Aug. 6, 2024, 4:30 p.m.

Product(s) Impacted

Google Chrome

  • before 127.0.6533.72

Description

Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Weaknesses

CWE-416
Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CWE ID: 416

Date

Published: Aug. 6, 2024, 4:15 p.m.

Last Modified: Aug. 6, 2024, 4:30 p.m.

Status : Undergoing Analysis

CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

More info

Source

chrome-cve-admin@google.com

References

https://chromereleases.googleblog.com/ chrome-cve-admin@google.com

https://issues.chromium.org/ chrome-cve-admin@google.com