CVE-2024-5835: Heap buffer overflow in Tab Groups
Chromium: CVE-2024-5835 Heap buffer overflow in Tab Groups
Other sources
Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 126.0.6478.54 - Upgrade
Upgrade
Chromium (Tab Groups) / Google Chrometo a version that resolves this vulnerability.Fixed in 126.0.6478.54
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5835?
CVE-2024-5835 is classified as a high-severity vulnerability due to its potential to cause heap buffer overflow.
How do I fix CVE-2024-5835?
To fix CVE-2024-5835, users should update to Google Chrome version 126.0.6478.54 or later, or apply updates from Microsoft for Edge (Chromium-based).
Which software is affected by CVE-2024-5835?
CVE-2024-5835 affects Google Chrome up to version 126.0.6478.54, Microsoft Edge (Chromium-based), and specific versions of Fedora.
Is CVE-2024-5835 exploited in the wild?
As of now, there is no public information indicating that CVE-2024-5835 is actively being exploited in the wild.
What causes CVE-2024-5835 vulnerability?
CVE-2024-5835 is caused by a heap buffer overflow in the Chromium engine used in various web browsers.