Unrated severityNVD Advisory· Published Feb 6, 2024· Updated May 15, 2025
CVE-2024-1284
CVE-2024-1284
Description
Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected products
4- osv-coords3 versionspkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/nodejs-electron&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/opera&distro=openSUSE%20Leap%2015.5%20NonFree
< 121.0.6167.184-1.1+ 2 more
- (no CPE)range: < 121.0.6167.184-1.1
- (no CPE)range: < 27.3.3-1.1
- (no CPE)range: < 107.0.5045.21-lp155.3.36.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop.htmlmitre
- issues.chromium.org/issues/41494539mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KN32XXNHIR6KBS4BYQTZV2JQFN4D6ZSE/mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WSCIL2WH2L4R4KWSRCTDWBPAMOJIYBJE/mitre
News mentions
0No linked articles in our index yet.