CRITICAL

CVE-2024-5274

Google Chrome 2024-05-28 CVSS v3.1
CVSS
9.6
KEV

Description

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

Type confusion vulnerability in Google's V8 JavaScript engine allows a remote attacker to achieve arbitrary code execution through a maliciously crafted HTML page. The vulnerability affects Chrome versions prior to 125.0.6422.112, and while the sandbox is mentioned, the flaw enables code execution within that sandbox context.

Mitigation

Update Google Chrome to version 125.0.6422.112 or later to patch the V8 type confusion vulnerability.

Proof of Concept

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

7.47%
Probability of exploitation in next 30 days
94.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE