CVE-2024-6994: Heap buffer overflow in Layout
Chromium: CVE-2024-6994 Heap buffer overflow in Layout
Other sources
Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6994?
CVE-2024-6994 has been classified as a high-severity vulnerability due to the heap buffer overflow risk it presents.
How do I fix CVE-2024-6994?
To address CVE-2024-6994, update Microsoft Edge (Chromium-based) to the latest version or ensure Google Chrome is upgraded beyond version 127.0.6533.72.
Which versions of Microsoft Edge are affected by CVE-2024-6994?
CVE-2024-6994 affects Microsoft Edge versions up to 127.0.2651.74.
Which versions of Google Chrome are impacted by CVE-2024-6994?
CVE-2024-6994 impacts Google Chrome versions up to 127.0.6533.72.
Is CVE-2024-6994 related to Chrome or Edge?
CVE-2024-6994 is primarily associated with the Chromium project and affects both Google Chrome and Microsoft Edge.