CRITICAL

CVE-2024-4947

Google Chrome 2024-05-15 CVSS v3.1
CVSS
9.6
KEV

Description

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

A type confusion vulnerability in the V8 JavaScript engine allows remote attackers to execute arbitrary code via a crafted HTML page. The flaw exploits how V8 handles object type verification, potentially bypassing sandbox containment to achieve code execution.

Mitigation

Update Google Chrome to version 125.0.6422.60 or later to patch the V8 type confusion vulnerability.

Proof of Concept

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

15.24%
Probability of exploitation in next 30 days
96.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE