CVE-2024-1670 is a high-severity use-after-free vulnerability in Google Chrome's Mojo component, affecting versions prior to 122.0.6261.57, as well as Fedora Project's Chrome and Fedora distributions. This flaw allows a remote attacker to potentially corrupt heap memory and achieve high impact on confidentiality, integrity, and availability by enticing a user to visit a specially crafted HTML page. While the CVSS score is 8.8 (High), there is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage, indicating a low immediate threat despite its technical severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 122.0.6261.57, < 122.0.6261.57CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 122.0.6261.57CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.