Google · Google Chrome · CVE-2024-3171
Name of the Vulnerable Software and Affected Versions:
Google Chrome versions prior to 122.0.6261.57
Description:
The issue is related to a use after free vulnerability in the Accessibility component of Google Chrome. This vulnerability can be exploited by a remote attacker who convinces a user to perform specific UI gestures, potentially leading to heap corruption. The attacker must convince the user to engage in specific UI gestures to exploit the vulnerability.
Recommendations:
For versions prior to 122.0.6261.57, update to version 122.0.6261.57 or later to resolve the issue. As a temporary workaround, consider restricting access to the Accessibility component until a patch is applied. Avoid using specific UI gestures that may trigger the vulnerability until the issue is resolved.