Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
CVE has been recently published to the CVE List and has been received by the NVD.
Products
Google Chrome
- before 128.0.6613.137
Source
chrome-cve-admin@google.com
Tags
CVE-2024-8639 details
Published : Sept. 11, 2024, 2:15 p.m.
Last Modified : Sept. 11, 2024, 4:26 p.m.
Last Modified : Sept. 11, 2024, 4:26 p.m.
Description
Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-416 | Use After Free | Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code. |
References
URL | Source |
---|---|
https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html | chrome-cve-admin@google.com |
https://issues.chromium.org/issues/362658609 | chrome-cve-admin@google.com |
This website uses the NVD API, but is not approved or certified by it.