CVE-2024-6777Use After Free in Google Chrome

CWE-416Use After Free7 documents7 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 84.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateAug 14

Description

Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5google/chrome126.0.6478.182126.0.6478.182
NVDgoogle/chrome< 126.0.6478.182
debiandebian/chromium< chromium 126.0.6478.182-1~deb12u1 (bookworm)
Debianchromium/chromium< 126.0.6478.182-1~deb12u1+2

🔴Vulnerability Details

2
GHSA
GHSA-w2v8-c457-cjvf: Use after free in Navigation in Google Chrome prior to 1262024-07-17
OSV
CVE-2024-6777: Use after free in Navigation in Google Chrome prior to 1262024-07-16

📋Vendor Advisories

4
Palo Alto
PAN-SA-2024-0007 Prisma Browser: Monthly Vulnerability Updates2024-08-14
Chrome
Stable Channel Update for Desktop: CVE-2024-67752024-07-16
Microsoft
Chromium: CVE-2024-6777 Use after free in Navigation2024-07-09
Debian
CVE-2024-6777: chromium - Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an...2024