PT-2024-4298 · Google+4 · Google Chrome+4

David Sievers

+1

·

Published

2024-05-21

·

Updated

2024-12-19

·

CVE-2024-5159

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 125.0.6422.76
Description The issue is related to a heap buffer overflow in the ANGLE library used by Google Chrome, allowing a remote attacker to perform an out of bounds memory read via a crafted HTML page. This can potentially lead to the execution of arbitrary code. The vulnerability is associated with a type confusion error that can be activated on a specially crafted malicious HTML page.
Recommendations For Google Chrome versions prior to 125.0.6422.76, update to version 125.0.6422.76 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted HTML pages that could exploit the heap buffer overflow in the ANGLE library. Restrict access to potentially malicious web content to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10294
ALT-PU-2024-11865
ALT-PU-2024-14286
ALT-PU-2024-14830
ALT-PU-2024-8361
BDU:2024-04785
CVE-2024-5159
DSA-5696-1
MGASA-2024-0194
OPENSUSE-SU-2024:0137-1
OPENSUSE-SU-2024:13988-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os