CVE-2024-10488

Published Oct 29, 2024

Last updated 16 days ago

Overview

Description
Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

chrome-cve-admin@google.com
CWE-416

Social media

Hype score
Not currently trending
  1. مجددا برای مرورگر کروم ۲ آسیب پذیری با کدهای شناسایی CVE-2024-10487 و CVE-2024-10488 منتشر شده است. آسیب پذیری اول از نوع RCE بوده و آسیب پذیری دوم که مربوط به webRTC مرورگر می باشد موجب کنترل کامل بر روی سیستم قربانی می شود . https://t.co/Y2P1U3epiq https://t.co/OE57u5qtNT

    @AmirHossein_sec

    1 Nov 2024

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Chrome Update Alert Google has issued an update (versions 130.0.6723.91/.92) for all platforms. Patched: CVE-2024-10487: Out-of-Bounds Write CVE-2024-10488: Use After Free Update Chrome now! #CyberSecurity #ChromeUpdate https://t.co/YDRhRbNAED

    @redfoxsec

    1 Nov 2024

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. #CVE Chromium: CVE-2024-10488 Use after free in WebRTC https://t.co/ssgV0qg2yx

    @ComputerPunks

    31 Oct 2024

    37 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CRITICAL VULNERABILITIES Google Chrome: Stable Channel Update for Desktop URL: https://t.co/Hxvyb5zmP8 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8 CVEs: CVE-2024-10487, CVE-2024-10488 #chrome #Google #UPDATETODAY

    @CharyyevPerman

    31 Oct 2024

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-10488 Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity High) https://t.co/16gx37XFVJ

    @VulmonFeeds

    30 Oct 2024

    65 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  6. (CVE-2024-10488)[374310077][datachannel]UaF in WebRTC https://t.co/lPbXLk9djX Reported by Cassidy Kim(@cassidy6564)

    @xvonfers

    30 Oct 2024

    682 Impressions

    1 Retweet

    4 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  7. Google fixes CVE-2024-10487 and CVE-2024-10488 in latest Chrome version #GoogleChrome #CVE-2024-10487 #CVE-2024-10488 https://t.co/saE7xP3PSE

    @pravin_karthik

    30 Oct 2024

    41 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  8. Chromeで重大(Critical)な脆弱性が修正。CVE-2024-10487はDawnグラフィックライブラリにおける境界外書き込み。深刻度高の解放後メモリ使用CVE-2024-10488も修正されている。 https://t.co/PoLoJST68s

    @__kokumoto

    30 Oct 2024

    614 Impressions

    2 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2024-10488 Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium s… https://t.co/Fh7b2fYZvh

    @CVEnew

    29 Oct 2024

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes