CVE-2024-5499: Chrome Browser Security Fixes339877167 High Out of bounds write in Streams API330759272 High CVE-2024-5274 Type Confusion in V8
Chromium: CVE-2024-5499 Out of bounds write in Streams API
Other sources
Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 125.0.6422.141Patch CVE-2024-5499 - Upgrade
Upgrade
Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 125.0.6422.141Patch CVE-2024-5499
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5499?
CVE-2024-5499 is classified as a high severity vulnerability due to its potential to allow out of bounds write errors.
How do I fix CVE-2024-5499?
To mitigate CVE-2024-5499, update your Chromium-based browsers, such as Google Chrome and Microsoft Edge, to the latest version.
Which versions of Google Chrome are affected by CVE-2024-5499?
Google Chrome versions prior to 125.0.6422.141 are affected by CVE-2024-5499.
Is Microsoft Edge affected by CVE-2024-5499?
Yes, Microsoft Edge (Chromium-based) is affected by CVE-2024-5499 and should be updated accordingly.
Which Fedora versions are impacted by CVE-2024-5499?
Fedora versions 39 and 40 are impacted by CVE-2024-5499 and require updates to address the vulnerability.