Google · Google Chrome · CVE-2024-2173
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 122.0.6261.111
**Description**
The issue is related to an out of bounds memory access in V8, which can be exploited by a remote attacker using a crafted HTML page, potentially allowing the execution of arbitrary code or causing a denial of service. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Technical details about exploitation include:
- **API Endpoints:** None specified
- **Vulnerable Parameters or Variables:** None specified
- **Function Names:** None specified, but the issue is related to a missing bounds check in the tier-up of the `wasm-to-js` wrapper.
**Recommendations**
For Google Chrome versions prior to 122.0.6261.111, update to version 122.0.6261.111 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable HTML pages until the update is applied.