CVE-2024-9957: Use after free in UI
Chromium: CVE-2024-9957 Use after free in UI
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9957?
CVE-2024-9957 has been classified as a high severity vulnerability due to its potential impact on system security.
How do I fix CVE-2024-9957?
To remediate CVE-2024-9957, users should update Google Chrome to version 130.0.6723.58 or later and ensure Microsoft Edge (Chromium-based) is also up-to-date.
Which products are affected by CVE-2024-9957?
CVE-2024-9957 affects Google Chrome versions prior to 130.0.6723.58 and certain versions of Microsoft Edge (Chromium-based).
When was CVE-2024-9957 first reported?
CVE-2024-9957 was first reported in October 2024 following updates made to the Chromium base.
Is there a workaround for CVE-2024-9957?
There are no known workarounds for CVE-2024-9957, so it is recommended to apply the available updates.