ZDI-CAN-23793: ZDI-25-027: (Pwn2Own) Google Chrome VideoFrame Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Google Chrome. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2024-2886.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23793?
ZDI-CAN-23793 has been assigned a CVSS rating of 5, indicating a medium severity level.
How do I fix ZDI-CAN-23793?
To mitigate ZDI-CAN-23793, ensure that you update your Google Chrome installation to the latest version.
What type of attacks are possible with ZDI-CAN-23793?
ZDI-CAN-23793 allows remote attackers to execute arbitrary code by tricking users into visiting a malicious page or opening a malicious file.
Does ZDI-CAN-23793 require user interaction to be exploited?
Yes, ZDI-CAN-23793 requires user interaction as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-CAN-23793?
ZDI-CAN-23793 affects installations of Google Chrome.