CVE-2024-5842: Use after free in Browser UI
Chromium: CVE-2024-5842 Use after free in Browser UI
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 126.0.6478.54 - Upgrade
Upgrade
Chromium (Google Chrome/Edge Chromium-based)to a version that resolves this vulnerability.Fixed in 126.0.6478.54
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5842?
CVE-2024-5842 is classified as a high severity vulnerability due to a use after free issue in Chromium.
How do I fix CVE-2024-5842?
To fix CVE-2024-5842, update Google Chrome to version 126.0.6478.54 or later, or ensure you are using the latest version of Microsoft Edge (Chromium-based).
Which software is affected by CVE-2024-5842?
CVE-2024-5842 affects Google Chrome versions earlier than 126.0.6478.54 and certain versions of Microsoft Edge (Chromium-based).
What type of vulnerability is CVE-2024-5842?
CVE-2024-5842 is categorized as a memory corruption vulnerability, specifically a use after free condition.
How was CVE-2024-5842 reported?
CVE-2024-5842 was assigned by the Chrome security team after discovering the vulnerability through internal testing.