CVE-2024-5274
KEV PoC mass1Google Chrome V8 Type Confusion Allows In-Sandbox RCE via Crafted HTML Pages
CISA: Google Chromium V8 Type Confusion Vulnerability
CVE-2024-5274 is a type confusion flaw (CWE-843) in the V8 JavaScript engine of Google Chrome prior to 125.0.6422.112. A remote attacker can trigger it by persuading a user to open or interact with a crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code inside the browser's sandbox, and the scope-changed CVSS scoring indicates potential impact beyond the browser process itself. Anyone running an affected Chrome or Chromium build, including Chromium-derived distributions such as Fedora's Chromium package, is exposed. The flaw was added to CISA's KEV on 2024-05-28, a public PoC reference exists, and related news reports describe it as actively exploited in the wild.
What to do: Upgrade Google Chrome to 125.0.6422.112 or later and confirm the build via chrome://version; Fedora users and users of Chromium-derived browsers should install the corresponding updated packages from their vendor. Because the flaw is listed in CISA KEV, federal agencies and targeted organizations must apply the vendor fix or discontinue use per the required action, and all users should avoid untrusted web content until patched.
| Google Chrome (Chromium V8 engine) | all versions prior to 125.0.6422.112 |
| Fedora Project Fedora (Chromium browser package) | versions shipping a vulnerable V8 engine; fixed version not specified in available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- Affected
- Google Chromium V8
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlefedoraproject
- Products
- chrome, fedora
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H