CVE-2024-7017: Inappropriate implementation in DevTools
Published May 1, 2024
·Updated
Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Credit
Allen Ding
Affected Software
6 affected componentsFixes available
Google Chrome<126.0.6478.182
All of the following
Google Chrome<126.0.6478.182
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Google Chrome<126.0.6478.182
126.0.6478.182
Event History
May 1, 2024
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Nov 14, 2025
CVE Published
via MITRE·02:29 AM
Data Sourced
via MITRE·02:29 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-7017?
CVE-2024-7017 has a high severity rating as it allows potential sandbox escape via a crafted HTML page.
2
How do I fix CVE-2024-7017?
To fix CVE-2024-7017, update Google Chrome to version 126.0.6478.182 or later.
3
Who is affected by CVE-2024-7017?
CVE-2024-7017 affects users of Google Chrome versions prior to 126.0.6478.182.
4
What type of attack does CVE-2024-7017 involve?
CVE-2024-7017 involves a potential remote attack that can perform a sandbox escape.
5
What is the impact of CVE-2024-7017?
The impact of CVE-2024-7017 could lead to unauthorized access and control over the affected system through the sandbox escape.