ZeroHour

CVE-2024-4761

KEVmass1

Actively Exploited Out-of-Bounds Write in Google Chrome V8 Engine (CVE-2024-4761)

CISA: Google Chromium V8 Out-of-Bounds Memory Write Vulnerability

CVSS 3.1
8.8 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2024-4761 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers the flaw by persuading a user to load a crafted HTML page, causing V8 to write beyond allocated memory bounds. Successful exploitation yields a high-impact memory corruption condition that can compromise confidentiality, integrity, and availability, potentially enabling arbitrary code execution within the browser process. All Google Chrome releases prior to 124.0.6367.207 are affected, as are Chromium-based distributions such as Fedora's Chromium package. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2024-05-16, confirming it is being exploited in the wild, and Google patched it in Chrome 124.0.6367.207.

What to do: Update Google Chrome to 124.0.6367.207 or later on all platforms and verify the running version at chrome://settings/help; Fedora administrators should install the patched chromium package from the Fedora repositories as soon as available. Because the flaw is confirmed exploited in the wild and listed in CISA KEV, treat patching as urgent, prioritizing workstations and servers with browsers used to access untrusted web content. As an interim mitigation, restrict high-risk users' web browsing or isolate browsers until updates are applied.

Affected
google chromeGoogle Chrome prior to 124.0.6367.207
google chromium (V8 engine)Chromium V8 as shipped in Chrome/Chromium prior to 124.0.6367.207
fedoraproject fedora (Chromium package)Fedora Chromium builds containing the affected V8 (fixed version not specified in source data)
Estimated exposure
massbillions of Chrome installations potentially affected (Chrome holds roughly 65% of global browser share) — Chrome is the world's dominant desktop and mobile browser, so the entire installed base running versions below 124.0.6367.207 — plausibly on the order of billions of users — is exposed until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news