HIGH
CVE-2024-4761
CVSS
8.8
KEV
Description
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
Out-of-bounds write vulnerability in the V8 JavaScript engine in Google Chrome prior to version 124.0.6367.207. A remote attacker can exploit this via a crafted HTML page to write memory outside allocated buffers, potentially achieving arbitrary code execution.
Mitigation
Update Google Chrome or Chromium-based browsers to version 124.0.6367.207 or later. Organizations should ensure automatic updates are enabled or deploy the patched version enterprise-wide.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
11.01%
Probability of exploitation in next 30 days
95.8th percentile
References
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_13.html
Vendor Advisory
https://issues.chromium.org/issues/339458194
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NTSN22LNYXMWHVTYNOYQVOY7VDZFHENQ/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WSUWM73ZCXTN62AT2REYQDD5ZKPFMDZD/
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4761
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.