PT-2024-5808 · Google+5 · Google Chrome+5
Published
2024-08-21
·
Updated
2025-07-02
·
CVE-2024-7967
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 128.0.6613.84
Microsoft Edge (affected versions not specified)
Description
A heap buffer overflow in the Fonts component of Google Chrome and Microsoft Edge allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This issue is related to the
UTF16TextIterator in the Blink Renderer and can lead to a segfault. The estimated number of potentially affected devices is not specified.Recommendations
For Google Chrome versions prior to 128.0.6613.84, update to version 128.0.6613.84 or later to resolve the issue.
For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the Fonts component or avoiding the use of crafted HTML pages until a patch is available.
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Google Chrome
Edge
Red Os