CVE-2024-7536 is a high-severity use-after-free vulnerability in Google Chrome's WebAudio component, affecting versions prior to 127.0.6533.99. A remote attacker could exploit this flaw by enticing a user to visit a crafted HTML page, potentially leading to heap corruption and arbitrary code execution. The CVSS score of 8.8 indicates a critical risk, with high impacts on confidentiality, integrity, and availability, requiring user interaction but no special privileges. While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered significant media and community discussion, suggesting a heightened awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 127.0.6533.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 127.0.6533.99, < 127.0.6533.99CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.