PT-2024-2545 · Google+6 · Google Chrome+6
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 123.0.6312.86
Microsoft Edge (affected versions not specified)
Description
A type confusion issue exists within the WebAssembly module of the browser. This occurs because the WASM module decoder lacks a proper check of the type section size in a branch of the
DecodeTypeSection() function. A remote attacker can exploit this by inducing the browser to load a specially crafted HTML page, which may lead to arbitrary code execution, denial of service, or information disclosure.Recommendations
Update Google Chrome to version 123.0.6312.86 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for Microsoft Edge.
Exploit
Fix
DoS
RCE
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Google Chrome
Edge
Red Os
Suse