CVE-2024-6988: Use after free in Downloads
Chromium: CVE-2024-6988 Use after free in Downloads
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6988?
CVE-2024-6988 is classified as a high severity vulnerability due to a use-after-free issue.
How do I fix CVE-2024-6988?
To fix CVE-2024-6988, update your Microsoft Edge or Google Chrome to version 127.0.6533.72 or later.
Which versions of Microsoft Edge are affected by CVE-2024-6988?
CVE-2024-6988 affects Microsoft Edge versions prior to 127.0.2651.74.
Is Apple iPhone OS vulnerable to CVE-2024-6988?
No, Apple iPhone OS is not affected by CVE-2024-6988.
Who assigned CVE-2024-6988?
CVE-2024-6988 was assigned by the Chrome security team.