CVE-2024-2887
Google Chrome WASM Improper Input Validation Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Type Confusion en WebAssembly en Google Chrome anterior a 123.0.6312.86 permitía a un atacante remoto ejecutar código arbitrario a través de una página HTML manipulada. (Severidad de seguridad de Chrome: alta)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Google Chrome. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the implementation of WebAssembly. By specifying a large number of structures, an attacker can cause the compiler to emit unsafe code. An attacker can leverage this vulnerability to execute code in the context of the current process at low integrity.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-03-26 CVE Reserved
- 2024-03-26 CVE Published
- 2024-08-01 CVE Updated
- 2024-08-25 First Exploit
- 2024-08-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (8)
URL | Date | SRC |
---|---|---|
https://github.com/rycbar77/CVE-2024-2887 | 2024-08-25 | |
https://github.com/PumpkinBridge/Chrome-CVE-2024-2887-RCE-Poc | 2024-08-25 | |
https://github.com/PumpkinBridge/Chrome-CVE-2024-2887-RCE-POC | 2024-08-25 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 123.0.6312.86 Search vendor "Google" for product "Chrome" and version "123.0.6312.86" | en |
Affected
|