CVE-2024-4060 is a high-severity Use-After-Free vulnerability in Dawn, affecting Google Chrome prior to version 124.0.6367.78, as well as Fedora Project's Chrome and Fedora. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a crafted HTML page. The CVSS score is 6.5 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and primarily leading to high availability impact. There is currently no evidence of active exploitation, nor are there public exploit codes available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 124.0.6367.78CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* | ||
>= 124.0.6367.78, < 124.0.6367.78CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.