ZeroHour

CVE-2024-7965

KEVmass

Chromium V8 heap corruption flaw (CVE-2024-7965) actively exploited in Chrome and Edge

CISA: Google Chromium V8 Inappropriate Implementation Vulnerability

CVSS 3.1
8.8 high
EPSS
19%p97
Published
()
KEV added
AI analysis

CVE-2024-7965 is an inappropriate implementation in the V8 JavaScript engine used by Google Chrome and other Chromium-based browsers, rated High severity (CVSS 3.1: 8.8) and tracked under CWE-787 (out-of-bounds write). It is triggered remotely when a user visits a crafted HTML page; the attack requires no privileges but does require user interaction, and successful exploitation potentially yields heap corruption with high impact on confidentiality, integrity and availability — in practice, compromise of the browser process. All Google Chrome installs prior to 128.0.6613.84 are affected, and the CISA/CPE data also places Microsoft's Chromium-based Edge in scope. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-28 and Google warned of active exploitation, with EPSS assigning an 18.5% next-30-day exploitation probability (97th percentile), though no public proof-of-concept code is known. Related coverage notes Google patched this alongside a string of actively exploited Chrome zero-days in August 2024.

What to do: Update Google Chrome to 128.0.6613.84 or later (Menu > Help > About Chrome, or enforce this version baseline via enterprise browser-update policies) and install Microsoft's corresponding Edge update that incorporates the Chromium V8 fix; other Chromium-based browsers should be updated to their upstream 128.0.6613.84-era builds. Because this is a KEV-listed bug exploited via malicious web pages and requires only that a user visit an attacker-crafted HTML page, treat browser patching as urgent and verify fleet-wide versions rather than relying on auto-update. Per the CISA KEV required action, apply the vendor mitigations or discontinue use of affected builds if patching is unavailable.

Affected
google chromeprior to 128.0.6613.84
google chromium (V8 engine)V8 in Chromium prior to the 128.0.6613.84 fix (CISA affected component: 'Google Chromium V8')
microsoft edge chromiumChromium-based Edge builds predating Microsoft's update incorporating the Chromium 128.0.6613.84 V8 fix (fixed Edge build number not specified in source data)
Estimated exposure
massorder of billions of users (Chrome alone has on the order of 3 billion+ active users, with Edge Chromium adding hundreds of millions more on unpatched builds) — Chrome is the world's dominant desktop browser with billions of reported active installs and Edge inherits the same V8 code, so effectively every unpatched Chrome/Edge/Chromium install is exposed until it receives the 128.0.6613.84-era…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googlemicrosoft
Products
chrome, edge chromium
Weakness
CWE-787, CWE-358
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news