CVE-2024-7534 is a high-severity heap buffer overflow vulnerability in Google Chrome (prior to version 127.0.6533.99) that could allow a remote attacker to corrupt heap memory via a specially crafted HTML page. With a CVSS score of 8.8, this vulnerability is easily exploitable over a network with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (not in KEV or Hot List) and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage. Users are advised to update Chrome immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 127.0.6533.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 127.0.6533.99, < 127.0.6533.99CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.