CVE-2024-0225: Use after free in WebGPU[41487330] High CVE-2024-1059 Use after free in WebRTCChromeOS Vulnerability Bug Fixes:[ ] High CVE-2024-0204 Users are able to bypass policies using kiosk apps in kiosk mode
Chromium: CVE-2024-0225 Use after free in WebGPU
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-0225?
CVE-2024-0225 has a high severity rating due to its potential to allow exploitation via a use-after-free vulnerability.
How do I fix CVE-2024-0225?
To mitigate CVE-2024-0225, users should update their Microsoft Edge or Google Chrome browsers to the latest version available.
Which versions are affected by CVE-2024-0225?
CVE-2024-0225 affects Microsoft Edge versions up to 120.0.2210.121 and Google Chrome versions up to 120.0.6099.199.
What platforms are affected by CVE-2024-0225?
CVE-2024-0225 impacts Chromium-based browsers including Microsoft Edge and Google Chrome across multiple operating systems.
Is CVE-2024-0225 being actively exploited?
As of now, there is no public information indicating active exploitation of CVE-2024-0225, but it is recommended to apply patches immediately.