CVE-2024-7025: Integer overflow in Layout
Chromium: CVE-2024-7025 Integer overflow in Layout
Other sources
Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7025?
CVE-2024-7025 is classified as a high severity vulnerability affecting HTTP requests in Chromium-based browsers.
How do I fix CVE-2024-7025?
To fix CVE-2024-7025, update Google Chrome to version 129.0.6668.89 or later, or update Microsoft Edge (Chromium-based) to the latest version.
Which browsers are affected by CVE-2024-7025?
CVE-2024-7025 affects Google Chrome versions prior to 129.0.6668.89 and Microsoft Edge (Chromium-based) versions that are not patched.
Has CVE-2024-7025 been resolved?
Yes, CVE-2024-7025 has been addressed in the Chrome and Edge updates released after the vulnerability was discovered.
What type of vulnerability is CVE-2024-7025?
CVE-2024-7025 is an integer overflow vulnerability that can potentially allow an attacker to execute arbitrary code.