Google · Google Chrome · CVE-2024-5498
Name of the Vulnerable Software and Affected Versions:
Google Chrome versions prior to 125.0.6422.141
Microsoft Edge (affected versions not specified)
Description:
The issue is related to a use after free vulnerability in the Presentation API of Google Chrome and Microsoft Edge browsers. This vulnerability can be exploited by a remote attacker by loading a specially crafted HTML page, potentially allowing them to impact the confidentiality, integrity, and availability of protected information. The exploitation is related to heap corruption.
Recommendations:
For Google Chrome versions prior to 125.0.6422.141, update to version 125.0.6422.141 or later to resolve the issue.
For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider avoiding the use of the Presentation API until a patch is available.