ZDI-25-027: (Pwn2Own) Google Chrome VideoFrame Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Google Chrome. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2024-2886.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-027?
The severity of ZDI-25-027 is rated with a CVSS score of 5.
How do I fix ZDI-25-027?
To fix ZDI-25-027, ensure that you are running the latest version of Google Chrome, as updates will contain patches for this vulnerability.
What are the impacts of ZDI-25-027?
ZDI-25-027 allows remote attackers to execute arbitrary code on affected installations of Google Chrome given that the user visits a malicious page or opens a malicious file.
Is user interaction required to exploit ZDI-25-027?
Yes, user interaction is required to exploit ZDI-25-027 as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-25-027?
ZDI-25-027 affects installations of Google Chrome.