Junglewise Threat Intelligence

CVE-2023-4762: Google Chromium V8 Type Confusion Vulnerability

CVE-2023-4762 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-02-06

Technologies: Google Chromium V8, Microsoft Edge, Opera Software Opera, Google Chrome. Vendors: Google, Microsoft, Opera Software.

Executive brief

A type confusion vulnerability in the V8 engine of Google Chromium allows a remote attacker to execute arbitrary code via a specially crafted HTML page. This vulnerability has been exploited in the wild and affects multiple Chromium-based browsers including Chrome, Edge, and Opera.

Affected products

  • Google Chrome prior to 116.0.5845.179
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2023-09-05: patched: Google Chrome version 116.0.5845.179 released to address the vulnerability.
  • 2024-02-06: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2024-02-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2024-02-06: exploited: Confirmed as exploited in the wild per CISA KEV entry.

Related threats