CVE-2024-8639
https://notcve.org/view.php?id=CVE-2024-8639
Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html https://issues.chromium.org/issues/362658609 • CWE-416: Use After Free •
CVE-2024-8638
https://notcve.org/view.php?id=CVE-2024-8638
Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html https://issues.chromium.org/issues/362539773 • CWE-416: Use After Free CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2024-8637
https://notcve.org/view.php?id=CVE-2024-8637
Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html https://issues.chromium.org/issues/361784548 • CWE-416: Use After Free •
CVE-2024-8636
https://notcve.org/view.php?id=CVE-2024-8636
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html https://issues.chromium.org/issues/361461526 • CWE-122: Heap-based Buffer Overflow CWE-416: Use After Free •
CVE-2024-40662
https://notcve.org/view.php?id=CVE-2024-40662
In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. • https://android.googlesource.com/platform/frameworks/base/+/e7af00cafb52a25933ec4edb80c5111d42af0237 https://source.android.com/security/bulletin/2024-09-01 • CWE-269: Improper Privilege Management •