CVE-2024-9126: Use after free in Internals
Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a series of curated UI gestures. (Chromium security severity: Medium)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 127.0.6533.88
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9126?
The severity of CVE-2024-9126 is classified as Medium.
How do I fix CVE-2024-9126?
To fix CVE-2024-9126, update Google Chrome to version 127.0.6533.88 or later.
What does CVE-2024-9126 exploit?
CVE-2024-9126 exploits a use after free vulnerability in the Internals of Google Chrome on iOS.
Can CVE-2024-9126 be exploited remotely?
Yes, CVE-2024-9126 can potentially be exploited by a remote attacker through specific UI gestures.
Which versions of Google Chrome are affected by CVE-2024-9126?
CVE-2024-9126 affects Google Chrome on iOS versions prior to 127.0.6533.88.