CVE-2024-7966
HIGHGoogle Chrome < 128.0.6613.84 - Out of Bounds Memory Access in Skia
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2024-7966. PoCs published by adminlove520, HyHy100.
AI-analyzed exploit summary The repository contains functional exploit code for multiple CVEs, including authentication bypass vulnerabilities in TOTOLINK devices and a scanner for Fortinet SSL VPN (CVE-2024-21762). The PoCs demonstrate the vulnerabilities with clear technical details and executable scripts.
Description
Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Exploits (2)
The repository contains functional exploit code for multiple CVEs, including authentication bypass vulnerabilities in TOTOLINK devices and a scanner for Fortinet SSL VPN (CVE-2024-21762). The PoCs demonstrate the vulnerabilities with clear technical details and executable scripts.
This PoC exploits a vulnerability in Chrome's Skia graphics engine (CVE-2024-7966) by generating a malformed Skia Picture (SKP) file that triggers a GPU process crash. The exploit involves crafting a malicious SKP file with a large shader payload to exploit a deserialization issue.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H