CVE-2024-2885 is a high-severity use-after-free vulnerability in Dawn, affecting Google Chrome versions prior to 123.0.6312.86, as well as Fedora Project's Chrome and Fedora distributions. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8, it carries a high impact on confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. While there is no public exploit code or KEV listing, media coverage indicates it was exploited as a zero-day at Pwn2Own, suggesting active exploitation prior to patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 123.0.6312.86CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* | ||
>= 123.0.6312.86, < 123.0.6312.86CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.