ZeroHour

CVE-2024-5274

KEV PoC mass1

Google Chrome V8 Type Confusion Allows In-Sandbox RCE via Crafted HTML Pages

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
9.6 critical
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2024-5274 is a type confusion flaw (CWE-843) in the V8 JavaScript engine of Google Chrome prior to 125.0.6422.112. A remote attacker can trigger it by persuading a user to open or interact with a crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code inside the browser's sandbox, and the scope-changed CVSS scoring indicates potential impact beyond the browser process itself. Anyone running an affected Chrome or Chromium build, including Chromium-derived distributions such as Fedora's Chromium package, is exposed. The flaw was added to CISA's KEV on 2024-05-28, a public PoC reference exists, and related news reports describe it as actively exploited in the wild.

What to do: Upgrade Google Chrome to 125.0.6422.112 or later and confirm the build via chrome://version; Fedora users and users of Chromium-derived browsers should install the corresponding updated packages from their vendor. Because the flaw is listed in CISA KEV, federal agencies and targeted organizations must apply the vendor fix or discontinue use per the required action, and all users should avoid untrusted web content until patched.

Affected
Google Chrome (Chromium V8 engine)all versions prior to 125.0.6422.112
Fedora Project Fedora (Chromium browser package)versions shipping a vulnerable V8 engine; fixed version not specified in available data
Estimated exposure
masson the order of billions of users (Chrome has 3+ billion users and roughly two-thirds desktop browser share) — Chrome is the world's dominant desktop browser with billions of active installations, and V8 is also shipped in Chromium derivatives such as Fedora's package, so the exposed population plausibly reaches the billions-of-users scale.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news