Unrated severityNVD Advisory· Published Jan 30, 2024· Updated Jun 3, 2025
CVE-2024-1077
CVE-2024-1077
Description
Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/opera&distro=openSUSE%20Leap%2015.5%20NonFree
< 121.0.6167.184-1.1+ 1 more
- (no CPE)range: < 121.0.6167.184-1.1
- (no CPE)range: < 107.0.5045.21-lp155.3.36.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_30.htmlmitre
- crbug.com/1511085mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUXJY3YC3VGIJW2AOHL4NZ7ZK7BRYWY/mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCVKRHRWPMITSVFBHQBSNXOVJAKT547Q/mitre
News mentions
0No linked articles in our index yet.