PT-2024-2545 · Google+6 · Google Chrome+6

·

CVE-2024-2887

·

Published

2024-03-26

·

Updated

2026-07-01

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 123.0.6312.86 Microsoft Edge (affected versions not specified)
Description A type confusion issue exists within the WebAssembly module of the browser. This occurs because the WASM module decoder lacks a proper check of the type section size in a branch of the DecodeTypeSection() function. A remote attacker can exploit this by inducing the browser to load a specially crafted HTML page, which may lead to arbitrary code execution, denial of service, or information disclosure.
Recommendations Update Google Chrome to version 123.0.6312.86 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability for Microsoft Edge.

Exploit

Fix

DoS

RCE

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-10294
ALT-PU-2024-14286
ALT-PU-2024-14830
ALT-PU-2024-4642
ALT-PU-2024-7309
BDU:2024-02532
CVE-2024-2887
DSA-5648-1
OPENSUSE-SU-2024:0122-1
OPENSUSE-SU-2024:13846-1
OPENSUSE-SU-2024:13953-1
OPENSUSE-SU-2024_0122-1
ZDI-24-366

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Edge
Red Os
Suse