CRITICAL
CVE-2024-5274
CVSS
9.6
KEV
Description
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
Type confusion vulnerability in Google's V8 JavaScript engine allows a remote attacker to achieve arbitrary code execution through a maliciously crafted HTML page. The vulnerability affects Chrome versions prior to 125.0.6422.112, and while the sandbox is mentioned, the flaw enables code execution within that sandbox context.
Mitigation
Update Google Chrome to version 125.0.6422.112 or later to patch the V8 type confusion vulnerability.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
7.47%
Probability of exploitation in next 30 days
94.3th percentile
References
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html
Release Notes
https://issues.chromium.org/issues/341663589
Exploit, Issue Tracking
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVC3FNI7HZLVSRIFBVUSBHI233DZYBKP/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6IBUYVPD4MIFQNNYBGAPI5MOECWXXOB/
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-5274
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.