ZeroHour

CVE-2024-4947

KEV PoC mass1

V8 Type Confusion in Google Chrome Actively Exploited by Lazarus Group

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
9.6 critical
EPSS
15%p97
Published
()
KEV added
AI analysis

CVE-2024-4947 is a type-confusion flaw (CWE-843) in the V8 JavaScript engine of Google Chrome, rated High by Chromium with a CVSS 3.1 score of 9.6. An attacker triggers it by luring a user to a crafted HTML page, causing V8 to misinterpret object types and enabling execution of arbitrary code inside the Chrome sandbox. Exploitation of the V8 bug alone keeps the attacker sandboxed, but it is a typical first stage of a browser exploit chain and can be paired with sandbox-escape techniques for broader system access. All Google Chrome installations prior to 125.0.6422.60 are affected, as are Fedora's packaged builds of Chrome/Chromium carrying the vulnerable V8 code. The vulnerability was added to CISA's KEV on 2024-05-20, has a public PoC referenced in Google's issue tracker, and public reporting ties its in-the-wild use to the North Korean Lazarus Group, which deployed the FudModule rootkit against infected Chrome users.

What to do: Upgrade Google Chrome to 125.0.6422.60 or later on all endpoints, and install the updated chromium packages published for Fedora, prioritizing this patch because the flaw is CISA KEV-listed with a mandatory mitigation deadline. Because Lazarus Group is exploiting this in the wild via crafted web pages, review endpoint telemetry for suspicious browser-borne activity and warn users against opening links from untrusted or decoy game/job-lure sites.

Affected
google chromeGoogle Chrome prior to 125.0.6422.60 (vulnerable V8 engine)
fedoraproject fedoraFedora-packaged Chromium/Chrome builds containing the vulnerable V8 (fixed via Fedora advisories; specific Fedora package versions not specified in the source d
Estimated exposure
masson the order of billions of Chrome installations (Chrome is the world's dominant desktop browser with roughly 65% market share and a multi-billion active… — Google Chrome is the most widely used browser worldwide at roughly 65% market share per public usage statistics, so nearly every internet-connected endpoint running Chrome below the fixed version is plausibly affected, with Fedora-hosted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news