ZDI-CAN-25396: ZDI-25-060: Google Chrome AI Manager Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Google Chrome. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-9954.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25396?
The ZDI-CAN-25396 vulnerability has a CVSS rating of 7, indicating it is a High severity issue.
What type of vulnerability is ZDI-CAN-25396?
ZDI-CAN-25396 is a remote code execution vulnerability that affects Google Chrome.
What is required for the exploitation of ZDI-CAN-25396?
Exploitation of ZDI-CAN-25396 requires user interaction, such as visiting a malicious page or opening a malicious file.
How do I fix ZDI-CAN-25396?
To fix ZDI-CAN-25396, users should update Google Chrome to the latest version as provided by Google.
Who is affected by ZDI-CAN-25396?
Users of Google Chrome installations are at risk from the ZDI-CAN-25396 vulnerability.