CVE-2024-4058Type Confusion in Google Chrome

CWE-843Type Confusion8 documents7 sources
Severity
8.8HIGHNVD
EPSS
6.3%
top 9.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateMay 19

Description

Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome124.0.6367.78124.0.6367.78
NVDgoogle/chrome< 124.0.6367.78
Debianchromium/chromium< 124.0.6367.78-1~deb12u1+2

Also affects: Fedora 40

🔴Vulnerability Details

4
OSV
CVE-2024-35928: In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init() Thi2024-05-19
GHSA
GHSA-23rw-79p3-xgcm: Type confusion in ANGLE in Google Chrome prior to 1242024-05-01
OSV
CVE-2024-4058: Type confusion in ANGLE in Google Chrome prior to 1242024-05-01
CVEList
CVE-2024-4058: Type confusion in ANGLE in Google Chrome prior to 1242024-05-01

📋Vendor Advisories

3
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2024-40582024-04-29
Microsoft
Chromium: CVE-2024-4058 Type Confusion in ANGLE2024-04-09
Debian
CVE-2024-4058: chromium - Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote...2024
CVE-2024-4058 — Type Confusion in Google Chrome | cvebase