VDB
CVE-2024-7025
CVE-2024-7025
PUBLISHED
Es existieren mehrere Schwachstellen in Google Chrome und Microsoft Edge, die zum aktuellen Zeitpunkt nicht im Detail beschrieben und veröffentlicht wurden. Diese Fehler bestehen in mehreren Komponenten wie V8, Layout oder Mojo und sind auf eine Reihe von sicherheitsrelevanten Problemen zurückzuführen, darunter Typverwechslung, unsachgemäße Implementierung, unzureichende Datenvalidierung und mehr. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um nicht näher spezifizierte Auswirkungen zu verursachen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.12% · 30.3th percentile
Risk Scores
EPSS Score
0.12%
30.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fedora | Fedora Linux | |
| Debian | Debian Linux | |
| IGEL | IGEL OS 12 | |
| Google Chrome Windows <129.0.6668.89/.90 | ||
| Google Chrome Mac <129.0.6668.89/.90 | ||
| Google Chrome Linux <129.0.6668.89 | ||
| Microsoft | Microsoft Edge <129.0.2792.79 | |
| Microsoft | Microsoft Edge Extended <128.0.2739.97 | |
| IGEL | IGEL OS 11 | |
| SUSE | SUSE openSUSE |
Exploit Intelligence
- https://issues.chromium.org/issues/367764861 (nist-nvd)
- CIRCL seen: CVE-2024-7025 (circl-sighting)
- CIRCL seen: CVE-2024-7025 (circl-sighting)
- https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop.html (circl)
Timeline
- Oct 1, 2024 CVE Published
- Oct 8, 2024 PoC Published
- Nov 27, 2024 PoC Published
- Nov 28, 2024 EPSS Score
- Dec 4, 2024 CVE Updated
- Dec 16, 2024 EPSS Score
- Jan 2, 2025 EPSS Score
- Jan 19, 2025 EPSS Score
- Feb 6, 2025 EPSS Score
- Feb 19, 2025 Coalition ESS Score
- Feb 23, 2025 EPSS Score
- Mar 12, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3060.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3060 advisory
- https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop.html advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#october-3-2024 advisory
- https://lists.debian.org/debian-security-announce/2024/msg00194.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-a3d9061962 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-ae299cc269 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-452b60addf advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-7aba3c1531 advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/EPRM6ZTLZBI4KDDDPXGZ5CBPVD2SA3XX/ advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SYPKGRQVF66ICD6CNLMEGRXEFBJME6TA/ advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/SYPKGRQVF66ICD6CNLMEGRXEFBJME6TA/ advisory
- https://kb.igel.com/security-safety/current/isn-2024-20-chromium-vulnerabilities advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/GYIF7RESU4PKGREHH5YVHUYYGB57P4CQ/ advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-18733ad580 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-35cc1d9ec0 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-791faa660a advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-60aa72a3e6 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-3ed223d8ce advisory