CVE-2024-2883 is a critical use-after-free vulnerability in ANGLE, affecting Google Chrome and Fedora versions prior to 123.0.6312.86. A remote attacker could exploit this by crafting a malicious HTML page, potentially leading to heap corruption. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over a network with low attack complexity, allowing for high impact on confidentiality, integrity, and availability. While there are no public exploits or Metasploit modules, SecurityWeek reported that this vulnerability was exploited as a zero-day at Pwn2Own, indicating active, targeted exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 123.0.6312.86CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* | ||
>= 123.0.6312.86, < 123.0.6312.86CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.