PT-2024-2545 · Microsoft +6 · Edge +6
Manfred Paul
·
Published
2024-03-26
·
Updated
2025-07-17
·
CVE-2024-2887
10
High
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
**Name of the Vulnerable Software and Affected Versions:**
Google Chrome versions prior to 123.0.6312.86
Microsoft Edge (Chromium-based) versions prior to 123.0.6312.86
Chromium versions prior to 123.0.6312.86
nodejs-electron versions 28.2.10-1.1
chromedriver versions 124.0.6367.201-1.1
chromium-gost versions 125.0.6422.112-alt0.c10.1
yandex-browser-certified (affected versions not specified)
MosOS (affected versions not specified)
OpenSUSE (affected versions not specified)
**Description:**
A type confusion vulnerability exists in the WebAssembly (WASM) module decoder in Google Chrome and Microsoft Edge (Chromium). This flaw allows a remote attacker to execute arbitrary code by crafting a malicious HTML page. The vulnerability is related to accessing a resource through incompatible types within the WASM module. Exploitation can lead to remote code execution.
**Recommendations:**
Google Chrome versions prior to 123.0.6312.86: Upgrade to version 123.0.6312.86 or later.
Microsoft Edge (Chromium-based) versions prior to 123.0.6312.86: Upgrade to version 123.0.6312.86 or later.
Chromium versions prior to 123.0.6312.86: Upgrade to version 123.0.6312.86 or later.
nodejs-electron version 28.2.10-1.1: Upgrade to a newer version.
chromedriver version 124.0.6367.201-1.1: Upgrade to a newer version.
chromium-gost version 125.0.6422.112-alt0.c10.1: Upgrade to a newer version.
yandex-browser-certified: Upgrade to a newer version.
MosOS: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OpenSUSE: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Type Confusion
Weakness Enumeration
Related Identifiers
Affected Products
References · 1160
- 🔥 https://github.com/mistymntncop/CVE-2023-4863⭐ 313 🔗 48 · Exploit
- 🔥 https://github.com/xcanwin/CVE-2023-4357-Chrome-XXE⭐ 214 🔗 34 · Exploit
- 🔥 https://github.com/ading2210/CVE-2024-6778-POC⭐ 90 🔗 13 · Exploit
- 🔥 https://github.com/mistymntncop/CVE-2024-5274⭐ 80 🔗 15 · Exploit
- 🔥 https://github.com/kaist-hacking/CVE-2023-6702⭐ 78 🔗 5 · Exploit
- 🔥 https://github.com/mistymntncop/CVE-2023-2033⭐ 62 🔗 18 · Exploit
- 🔥 https://github.com/OgulcanUnveren/CVE-2023-4357-APT-Style-exploitation⭐ 43 🔗 21 · Exploit
- 🔥 https://github.com/LiveOverflow/webp-CVE-2023-4863⭐ 48 🔗 7 · Exploit
- 🔥 https://github.com/buptsb/CVE-2023-4762⭐ 26 🔗 6 · Exploit
- 🔥 https://github.com/zckevin/CVE-2023-4762⭐ 26 🔗 6 · Exploit
- 🔥 https://github.com/tianstcht/CVE-2023-4427⭐ 26 🔗 4 · Exploit
- 🔥 https://github.com/sandumjacob/CVE-2023-2033-Analysis⭐ 19 🔗 2 · Exploit
- 🔥 https://github.com/UT-Security/cve-2023-5217-poc⭐ 15 🔗 5 · Exploit
- 🔥 https://github.com/wrv/cve-2023-5217-poc⭐ 15 🔗 5 · Exploit
- 🔥 https://github.com/rycbar77/CVE-2024-2887⭐ 13 🔗 3 · Exploit