CERT-In Vulnerability Note
CIVN-2024-0240
Multiple Vulnerabilities in Google Chrome
Original Issue Date:August 13, 2024
Severity Rating: HIGH
Software Affected
- Google Chrome versions prior to 127.0.6533.99/.100 for Windows and Mac.
- Google Chrome versions prior to 127.0.6533.99 for Linux.
Overview
Multiple vulnerabilities have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code on the targeted system.
Description
These vulnerabilities exist in Google Chrome due to Heap buffer overflow in Layout; Out of bounds memory access in ANGLE; Use after free in Sharing and WebAudio; Type Confusion and Inappropriate implementation in V8. An attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted web page.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned by Vendor:
https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html
References
Google Chrome
https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html
CVE Name
CVE-2024-7533
CVE-2024-7534
CVE-2024-7532
CVE-2024-7535
CVE-2024-7536
CVE-2024-7550
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|