CVE-2024-12694
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 18, 2024
Updated: Jan 3, 2025
CWE ID 416
Summary
CVE-2024-12694 is a high severity vulnerability affecting Google Chrome versions prior to 131.0.6778.204. This issue involves a use-after-free condition in the Compositing component, which can be exploited by a remote attacker. By constructing a maliciously crafted HTML page, the attacker may successfully corrupt the heap, potentially leading to code execution. This vulnerability poses a significant risk, as successful exploitation could result in a variety of malicious activities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.