CVE-2024-2887: Type Confusion in WebAssembly
Chromium: CVE-2024-2887 Type Confusion in WebAssembly
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2887?
CVE-2024-2887 is classified as a type confusion vulnerability that could potentially allow for remote code execution.
How do I fix CVE-2024-2887?
To fix CVE-2024-2887, users should update Google Chrome to version 123.0.6312.86 or later, or ensure that their Microsoft Edge (Chromium-based) browser is fully updated.
Which versions of Chrome are affected by CVE-2024-2887?
CVE-2024-2887 affects versions of Google Chrome prior to 123.0.6312.86.
Does CVE-2024-2887 affect Microsoft Edge?
Yes, Microsoft Edge (Chromium-based) is affected by CVE-2024-2887 since it incorporates Chromium.
What types of systems are at risk due to CVE-2024-2887?
CVE-2024-2887 poses a risk to any system running vulnerable versions of Google Chrome and Microsoft Edge (Chromium-based), including multiple distributions of Fedora.