CVE-2024-6990: Uninitialized Use in Dawn
Chromium: CVE-2024-6990 Uninitialized Use in Dawn
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6990?
CVE-2024-6990 is classified as a high-severity vulnerability affecting Chromium-based browsers.
How do I fix CVE-2024-6990?
To fix CVE-2024-6990, ensure your Google Chrome is updated to version 127.0.6533.88 or later, and Microsoft Edge to version 127.0.2651.86 or later.
What type of vulnerability is CVE-2024-6990?
CVE-2024-6990 is an uninitialized use vulnerability that can potentially lead to information disclosure.
Which software is affected by CVE-2024-6990?
CVE-2024-6990 affects Google Chrome versions prior to 127.0.6533.88 and Microsoft Edge (Chromium-based) versions prior to 127.0.2651.86.
Who is responsible for addressing CVE-2024-6990?
The vulnerability CVE-2024-6990 is addressed by Google as part of the Chromium project, which also affects Microsoft Edge.