CVE-2024-7965
KEVmassChromium V8 heap corruption flaw (CVE-2024-7965) actively exploited in Chrome and Edge
CISA: Google Chromium V8 Inappropriate Implementation Vulnerability
CVE-2024-7965 is an inappropriate implementation in the V8 JavaScript engine used by Google Chrome and other Chromium-based browsers, rated High severity (CVSS 3.1: 8.8) and tracked under CWE-787 (out-of-bounds write). It is triggered remotely when a user visits a crafted HTML page; the attack requires no privileges but does require user interaction, and successful exploitation potentially yields heap corruption with high impact on confidentiality, integrity and availability — in practice, compromise of the browser process. All Google Chrome installs prior to 128.0.6613.84 are affected, and the CISA/CPE data also places Microsoft's Chromium-based Edge in scope. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-28 and Google warned of active exploitation, with EPSS assigning an 18.5% next-30-day exploitation probability (97th percentile), though no public proof-of-concept code is known. Related coverage notes Google patched this alongside a string of actively exploited Chrome zero-days in August 2024.
What to do: Update Google Chrome to 128.0.6613.84 or later (Menu > Help > About Chrome, or enforce this version baseline via enterprise browser-update policies) and install Microsoft's corresponding Edge update that incorporates the Chromium V8 fix; other Chromium-based browsers should be updated to their upstream 128.0.6613.84-era builds. Because this is a KEV-listed bug exploited via malicious web pages and requires only that a user visit an attacker-crafted HTML page, treat browser patching as urgent and verify fleet-wide versions rather than relying on auto-update. Per the CISA KEV required action, apply the vendor mitigations or discontinue use of affected builds if patching is unavailable.
| google chrome | prior to 128.0.6613.84 |
| google chromium (V8 engine) | V8 in Chromium prior to the 128.0.6613.84 fix (CISA affected component: 'Google Chromium V8') |
| microsoft edge chromium | Chromium-based Edge builds predating Microsoft's update incorporating the Chromium 128.0.6613.84 V8 fix (fixed Edge build number not specified in source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- Affected
- Google Chromium V8
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown