CVE-2024-5436 is a critical type confusion vulnerability in Snapchat LensCore, affecting versions prior to 12.88. This flaw could allow an unauthenticated attacker to remotely trigger a denial of service or achieve arbitrary code execution. With a CVSS score of 9.8, it poses a significant risk, though there is currently no evidence of active exploitation, public exploit code, or notable community discussion. Upgrading to Snapchat version 12.88 or higher is strongly recommended to mitigate this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.88CPE matchmatch criteria | cpe:2.3:a:snap:snapchat_lenscore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.