CVE-2024-3171: Use after free in Accessibility
Published Dec 12, 2023
·Updated
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
Credit
ttt
Affected Software
2 affected componentsFixes available
Google Chrome<122.0.6261.57
122.0.6261.57
Google Chrome<122.0.6261.57
Event History
Dec 12, 2023
CVE Published
12:00 AM
Jul 16, 2024
CVE Published
via MITRE·10:14 PM
Data Sourced
via MITRE·10:14 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
Description
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-3171?
The severity of CVE-2024-3171 is classified as Medium by Chromium security.
2
How do I fix CVE-2024-3171?
To fix CVE-2024-3171, update Google Chrome to version 122.0.6261.57 or later.
3
What causes CVE-2024-3171?
CVE-2024-3171 is caused by a use-after-free vulnerability in Accessibility within Google Chrome.
4
Who is affected by CVE-2024-3171?
Users of Google Chrome versions prior to 122.0.6261.57 are affected by CVE-2024-3171.
5
Can CVE-2024-3171 be exploited remotely?
Yes, CVE-2024-3171 can potentially be exploited remotely through specific UI gestures.