CVE-2024-8362

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 3, 2024
Updated: Sep 4, 2024
CWE ID 416

Summary

CVE-2024-8362 is a vulnerability affecting Google Chrome versions prior to 128.0.6613.119 that allows remote attackers to exploit heap corruption via a specially crafted HTML page, classified as a high severity risk. The vulnerability arises from a "use after free" condition in the WebAudio component, leading to significant impacts on confidentiality, integrity, and availability. To mitigate this issue, users should upgrade their Chrome browser to the latest version provided in the update released on August 30, 2024. Failure to address this vulnerability could allow attackers to execute arbitrary code or manipulate user data without authorization. Organizations are urged to implement immediate updates and monitor for any signs of exploitation related to this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share