CVE-2024-6291: Use after free in Swiftshader
Chromium: CVE-2024-6291 Use after free in Swiftshader
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 126.0.6478.126 - Upgrade
Upgrade
Chromium (Google Chrome/Chromium-based browsers) - Swiftshaderto a version that resolves this vulnerability.Fixed in 126.0.6478.126
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6291?
The severity of CVE-2024-6291 is currently classified as high, due to the potential for exploitation in affected software.
How do I fix CVE-2024-6291?
To fix CVE-2024-6291, update Google Chrome or Microsoft Edge (Chromium-based) to version 126.0.6478.126 or later.
Which versions of software are affected by CVE-2024-6291?
CVE-2024-6291 affects Google Chrome versions up to 126.0.6478.126 and specific versions of Microsoft Edge and Fedora.
What type of vulnerability is CVE-2024-6291?
CVE-2024-6291 is categorized as a use after free vulnerability in Chromium.
Is there any workaround for CVE-2024-6291?
Currently, the recommended action for CVE-2024-6291 is to update to the latest versions of the affected browsers, as no official workarounds are provided.