CVE-2024-6989: High Use after free in Loader
Chromium: CVE-2024-6989 Use after free in Loader
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6989?
CVE-2024-6989 is classified as a high severity vulnerability due to its potential for exploitation.
How do I fix CVE-2024-6989?
To fix CVE-2024-6989, users should update Microsoft Edge and Google Chrome to the latest versions that address this vulnerability.
What platforms are affected by CVE-2024-6989?
CVE-2024-6989 affects Microsoft Edge (Chromium-based) and Google Chrome up to versions 127.0.2651.74 and 127.0.6533.72 respectively.
What type of vulnerability is CVE-2024-6989?
CVE-2024-6989 is a 'use after free' vulnerability which can lead to arbitrary code execution.
When was CVE-2024-6989 disclosed?
CVE-2024-6989 was disclosed by Google as part of their ongoing security updates for the Chromium project.