CVE-2024-10487: 375123371 Critical Out of bounds write in Dawn372269618 High CVE-2024-10231 Type Confusion in V8371011220 High CVE-2024-10229 Inappropriate implementation in Extensions40076120 Medium CVE-2024-9958 Inappropriate implementation in PictureInPicture328278718 Medium CVE-2024-9963 Insufficient data validation in Downloads
Chromium: CVE-2024-10487: Out of bounds write in Dawn
Other sources
Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10487?
CVE-2024-10487 has been classified with a high severity rating due to its potential impact on both Google Chrome and Microsoft Edge browsers.
How do I fix CVE-2024-10487?
To fix CVE-2024-10487, users should update to the latest version of Google Chrome or Microsoft Edge immediately.
Which versions of Microsoft Edge are affected by CVE-2024-10487?
Microsoft Edge versions up to but not including 130.0.2849.68 are affected by CVE-2024-10487.
Is Microsoft Edge (Chromium-based) affected by CVE-2024-10487?
Yes, Microsoft Edge (Chromium-based) is affected by CVE-2024-10487 and needs to be updated to mitigate the vulnerability.
What should I do if I am using an outdated version of Google Chrome concerning CVE-2024-10487?
If using an outdated version of Google Chrome, users should immediately update to the latest version to protect against CVE-2024-10487.