CVE-2024-7256: Insufficient data validation in Dawn
Chromium: CVE-2024-7256 Insufficient data validation in Dawn
Other sources
Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-7256?
CVE-2024-7256 is categorized as a moderate severity vulnerability.
How do I fix CVE-2024-7256?
To fix CVE-2024-7256, update Google Chrome to version 127.0.6533.88 or later, or update Microsoft Edge to version 127.0.2651.86 or later.
Which versions of Chrome are affected by CVE-2024-7256?
Chrome versions prior to 127.0.6533.88 are affected by CVE-2024-7256.
Is Microsoft Edge (Chromium-based) vulnerable to CVE-2024-7256?
Yes, Microsoft Edge (Chromium-based) versions prior to 127.0.2651.86 are vulnerable to CVE-2024-7256.
What does CVE-2024-7256 entail?
CVE-2024-7256 involves insufficient data validation within the browser, which may allow for potential security issues.