PT-2024-4297 · Google+4 · Google Chrome+4

Wgslfuzz

·

Published

2024-05-21

·

Updated

2024-12-20

·

CVE-2024-5160

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 125.0.6422.76
Description A heap buffer overflow issue in Dawn, a component of Google Chrome, allows a remote attacker to perform an out of bounds memory write via a crafted HTML page. This could potentially enable the attacker to execute arbitrary code. The issue is related to the WebGPU API and is considered to have a high security severity.
Recommendations For Google Chrome versions prior to 125.0.6422.76, update to version 125.0.6422.76 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted HTML pages that could exploit this vulnerability. Avoid using the affected Dawn component until a patch is applied. At the moment, there is no additional information about other mitigation measures.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10294
ALT-PU-2024-11865
ALT-PU-2024-14286
ALT-PU-2024-14830
ALT-PU-2024-8361
BDU:2024-04784
CVE-2024-5160
DSA-5696-1
MGASA-2024-0194
OPENSUSE-SU-2024:0137-1
OPENSUSE-SU-2024:13988-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os