CVE-2024-2886: 330575496 High Use after free in WebCodecs331237485 High CVE-2024-3157 Out of bounds write in Compositing330760873 High CVE-024-3159 Out of bounds memory access in V8330588502 High CVE-2024-2887 Type Confusion in WebAssembly325936438 High CVE-2024-2176 Use after free in FedCM
Chromium: CVE-2024-2886 Use after free in WebCodecs
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2886?
CVE-2024-2886 is considered a high-severity vulnerability due to its potential for exploitation via use after free conditions.
How do I fix CVE-2024-2886?
To fix CVE-2024-2886, update your Microsoft Edge (Chromium-based) or Google Chrome to the latest version available.
Which software is affected by CVE-2024-2886?
CVE-2024-2886 affects Google Chrome versions up to 123.0.6312.86 and various versions of Microsoft Edge as well as Fedora 38, 39, and 40.
Is CVE-2024-2886 actively exploited?
Yes, CVE-2024-2886 has been reported to be exploited in the wild, especially during events like Pwn2Own 2024.
What type of vulnerability is CVE-2024-2886?
CVE-2024-2886 is a use after free vulnerability which can lead to remote code execution.