CVE-2024-5436

Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.
References
Link Resource
https://hackerone.com/snapchat Third Party Advisory
https://hackerone.com/snapchat Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:snap:snapchat_lenscore:*:*:*:*:*:*:*:*

History

22 Jul 2025, 20:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-843
References () https://hackerone.com/snapchat - () https://hackerone.com/snapchat - Third Party Advisory
First Time Snap
Snap snapchat Lenscore
CPE cpe:2.3:a:snap:snapchat_lenscore:*:*:*:*:*:*:*:*

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://hackerone.com/snapchat - () https://hackerone.com/snapchat -
Summary
  • (es) La confusión de tipos en Snapchat LensCore podría provocar una denegación de servicio o la ejecución de código arbitrario antes de la versión 12.88. Recomendamos actualizar a la versión 12.88 o superior.

31 May 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-31 09:15

Updated : 2025-07-22 20:19


NVD link : CVE-2024-5436

Mitre link : CVE-2024-5436

CVE.ORG link : CVE-2024-5436


JSON object : View

Products Affected

snap

  • snapchat_lenscore
CWE
CWE-704

Incorrect Type Conversion or Cast

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')