CVE-2024-6998: Use after free in User Education
Chromium: CVE-2024-6998 Use after free in User Education
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6998?
CVE-2024-6998 is a use after free vulnerability identified in the Chromium codebase.
How do I fix CVE-2024-6998?
To address CVE-2024-6998, update Microsoft Edge to the latest version available or Google Chrome to version 127.0.6533.72 or later.
Which versions of Microsoft Edge are affected by CVE-2024-6998?
Microsoft Edge versions prior to 127.0.2651.74 are affected by CVE-2024-6998.
Is Google Chrome vulnerable to CVE-2024-6998?
Yes, Google Chrome versions earlier than 127.0.6533.72 are vulnerable to CVE-2024-6998.
Has a patch been released for CVE-2024-6998?
Yes, patches addressing CVE-2024-6998 have been released in the latest updates for Microsoft Edge and Google Chrome.