CVE-2024-5846Disclosure(fedoraproject / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fedoraproject chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • fedora

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
chromefedora

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-23: 1Mentions · 2026-07-05: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-07-05: 1Technical Details · 2026-06-23: 1Technical Details · 2026-07-05: 106-2307-05
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-231
Disclosure1
2026-07-051
Patch1
Full discourse2 posts
  • kokumօtօ@__kokumoto
    Disclosure

    Difyでテナント跨ぎでデータが漏洩する脆弱性群DifyTapについて。CVE-2024-5846、CVE-2026-41947、CVE-2026-41948、CVE-2026-41949、CVE-2026-41950。CVE-2026-41948は未修正。それ以外はバージョン1.14.2で修正。 https://thehackernews.com/2026/06/researchers-detail-difytap-flaws-in.html?m=1

    Post summary

    Researchers announced a set of DifyTap vulnerabilities that allow tenant‑cross data leakage, noting that most have been patched in v1.14.2 except CVE‑2026‑41948.

    00020898
    7.7K followersView on X
  • Israel@f1tym1
    Patch

    Update: Dify addressed all four DifyTap vulnerabilities in version 1.14.2, with the PDFium library (CVE-2024-5846) separately updated in December 2025—meaning the use-after-free flaw had been shipped for approximately 18 months before remediation. https://ift.tt/i2udGRs

    Post summary

    Dify released version 1.14.2 and an updated PDFium library to fix all DifyTap vulnerabilities, including CVE‑2024‑5846—a use‑after‑free flaw that had existed for roughly 18 months before remediation.

    0000054
    1.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora39--
OSfedoraprojectfedora40--
Appgooglechrome---

Explore more