ZeroHour

CVE-2024-7971

KEV PoC mass1

Type Confusion in Google Chromium V8 Enables Heap Corruption via Malicious Pages

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
9.6 critical
EPSS
21%p97
Published
()
KEV added
AI analysis

Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a remote attacker trigger heap corruption through a specially crafted HTML page. The attack is triggered simply by a user loading an attacker-controlled web page, with no other interaction required. Successful exploitation of heap corruption in a browser JavaScript engine typically gives the attacker code execution within the browser process, a common first step toward broader system compromise. All users of Chromium-based browsers are affected, including Google Chrome, Microsoft Edge, Opera, and any other product embedding Chromium V8. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-08-26, confirming active in-the-wild exploitation, and EPSS assigns a 20.7% probability of exploitation within 30 days (97th percentile).

What to do: Update all Chromium-based browsers (Chrome, Edge, Opera, Brave) to the vendors' patched releases immediately and verify the installed version via chrome://version or edge://version. Per CISA's KEV required action, apply vendor mitigations or discontinue use if patches are unavailable; until patching completes, treat web browsing on high-value systems with caution and watch for vendors to publish the specific fixed version numbers.

Affected
Google Chromium V8 JavaScript engine
Google Chrome (Chromium-based)All versions built on the affected V8 engine prior to vendor updates (not specified in source data)
Microsoft Edge (Chromium-based)All versions built on the affected V8 engine prior to vendor updates (not specified in source data)
Opera (Chromium-based)All versions built on the affected V8 engine prior to vendor updates (not specified in source data)
Estimated exposure
massbillions of users/installations (Chrome alone is estimated at ~3 billion+ users, plus Edge, Opera, Brave and other Chromium browsers) — Chrome holds roughly two-thirds of global browser market share with an installed base estimated in the billions, and Chromium V8 also ships in Edge, Opera and Brave, so essentially every unpatched Chromium-based browser is exposed until…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googlemicrosoft
Products
chrome, edge
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news