PT-2024-6337 · Google+4 · Skia+5

Hyhy_100

+1

·

Published

2024-08-16

·

Updated

2025-07-02

·

CVE-2024-8193

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 128.0.6613.113
Description The issue is related to a heap buffer overflow in the Skia graphics library of Google Chrome, which can be exploited by a remote attacker who has compromised the renderer process. This can potentially lead to heap corruption via a crafted HTML page. The severity of this issue is considered high.
Recommendations For Google Chrome versions prior to 128.0.6613.113, update to version 128.0.6613.113 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable HTML pages until the update is applied.

Fix

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17740
ALT-PU-2025-2945
ALT-PU-2025-4366
ALT-PU-2025-7539
ALT-PU-2025-8547
BDU:2024-07374
CVE-2024-8193
DSA-5761-1
INFESA-2024_0001
INFESA-2024_0002
MGASA-2024-0321
OPENSUSE-SU-2024:0267-1
OPENSUSE-SU-2024:14303-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
Skia