CVE-2024-3157
CRITICALGoogle Chrome <123.0.6312.122 - Memory Corruption
Title source: llmDescription
Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)
References (5)
Scores
CVSS v3
9.6
EPSS
0.0054
EPSS Percentile
67.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Classification
CWE
CWE-787
Status
published
Affected Products (4)
google/chrome
< 123.0.6312.122
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
Timeline
Published
Apr 10, 2024
Tracked Since
Feb 18, 2026