CVE-2024-6102: Out of bounds memory access in Dawn
Chromium: CVE-2024-6102: Out of bounds memory access in Dawn
Other sources
Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 126.0.6478.114 - Upgrade
Upgrade
Chromium / Google Chrome (Dawn)to a version that resolves this vulnerability.Fixed in 126.0.6478.114
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6102?
CVE-2024-6102 is classified as a high-severity vulnerability affecting Chromium-based browsers.
How do I fix CVE-2024-6102?
To fix CVE-2024-6102, update Google Chrome to version 126.0.6478.114 or later and ensure you are using the latest version of Microsoft Edge (Chromium-based).
Which versions of Chrome are affected by CVE-2024-6102?
CVE-2024-6102 affects Google Chrome versions prior to 126.0.6478.114.
Does CVE-2024-6102 affect Microsoft Edge?
Yes, CVE-2024-6102 affects Microsoft Edge (Chromium-based) as it utilizes the Chromium engine.
What types of issues does CVE-2024-6102 address?
CVE-2024-6102 addresses an out-of-bounds memory access issue that can lead to potentially exploitable vulnerabilities.