CVE-2024-5436: Type Confusion in Snapchat Lenscore
Published May 31, 2024
·Updated
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.
Affected Software
2 affected components
Snapchat LensCore<12.88
Snap Snapchat LensCore<12.88
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.88
Event History
May 31, 2024
CVE Published
via MITRE·08:11 AM
Data Sourced
via MITRE·08:11 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Apr 6, 58462
Event
via NVD·05:19 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-5436?
CVE-2024-5436 has a high severity rating due to potential denial of service or arbitrary code execution risks.
2
How do I fix CVE-2024-5436?
To fix CVE-2024-5436, upgrade to Snapchat LensCore version 12.88 or above.
3
What type of vulnerability is CVE-2024-5436?
CVE-2024-5436 is categorized as a type confusion vulnerability.
4
What are the potential impacts of CVE-2024-5436?
The potential impacts of CVE-2024-5436 include denial of service and arbitrary code execution.
5
Which versions of Snapchat LensCore are affected by CVE-2024-5436?
CVE-2024-5436 affects all versions of Snapchat LensCore prior to version 12.88.