CVE-2024-5497: High Out of bounds memory access in Browser UI344608204 High CVE-2024-6100 Type Confusion in V8High CVE-2024-36971 Linux Kernel Vulnerability
Chromium: CVE-2024-5497 Out of bounds memory access in Keyboard Inputs
Other sources
Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Chromium / Google Chrome / Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 125.0.6422.141
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5497?
CVE-2024-5497 is rated as a high-severity vulnerability affecting Chromium-based browsers.
How do I fix CVE-2024-5497?
To fix CVE-2024-5497, update your browser to the latest version of Google Chrome or Microsoft Edge.
Which software is affected by CVE-2024-5497?
CVE-2024-5497 affects Google Chrome versions up to 125.0.6422.141 and Microsoft Edge (Chromium-based) versions.
What type of vulnerability is CVE-2024-5497?
CVE-2024-5497 is classified as an out-of-bounds memory access vulnerability.
Who is responsible for resolving CVE-2024-5497?
Google Chrome development team is responsible for addressing CVE-2024-5497, with Microsoft Edge relying on their updates.