CVE-2024-6772: Inappropriate implementation in V8
Chromium: CVE-2024-6772 Inappropriate implementation in V8
Other sources
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 126.0.6478.182 - Upgrade
Upgrade
Chromium (V8)to a version that resolves this vulnerability.Fixed in 126.0.6478.182
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6772?
CVE-2024-6772 has been classified with a high severity level due to its inappropriate implementation that could lead to potential exploitation.
How do I fix CVE-2024-6772?
To resolve CVE-2024-6772, update Google Chrome to version 126.0.6478.182 or later, or Microsoft Edge (Chromium-based) to the latest available version.
What software is affected by CVE-2024-6772?
CVE-2024-6772 affects Google Chrome versions up to 126.0.6478.182 and Microsoft Edge versions up to 126.0.2592.113.
Is Microsoft Edge (Chromium-based) vulnerable to CVE-2024-6772?
Yes, Microsoft Edge (Chromium-based) is vulnerable to CVE-2024-6772 unless updated to the latest version that addresses this issue.
Who is responsible for addressing CVE-2024-6772?
Google is responsible for addressing CVE-2024-6772 as it was assigned by Chrome, with updates provided for affected Microsoft products.