CRITICAL
CVE-2024-4947
CVSS
9.6
KEV
Description
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
A type confusion vulnerability in the V8 JavaScript engine allows remote attackers to execute arbitrary code via a crafted HTML page. The flaw exploits how V8 handles object type verification, potentially bypassing sandbox containment to achieve code execution.
Mitigation
Update Google Chrome to version 125.0.6422.60 or later to patch the V8 type confusion vulnerability.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
15.24%
Probability of exploitation in next 30 days
96.7th percentile
References
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html
Vendor Advisory
https://issues.chromium.org/issues/340221135
Exploit, Issue Tracking
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NTSN22LNYXMWHVTYNOYQVOY7VDZFHENQ/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WSUWM73ZCXTN62AT2REYQDD5ZKPFMDZD/
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4947
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.