Executive brief
A type confusion vulnerability in the V8 engine of Google Chromium allows a remote attacker to execute arbitrary code via a specially crafted HTML page. This vulnerability has been exploited in the wild and affects multiple Chromium-based browsers including Chrome, Edge, and Opera.
Affected products
- Google Chrome prior to 116.0.5845.179
- Microsoft Edge
- Opera Software Opera
Timeline
- 2023-09-05: patched: Google Chrome version 116.0.5845.179 released to address the vulnerability.
- 2024-02-06: disclosed: Vulnerability published and added to CISA KEV catalog.
- 2024-02-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2024-02-06: exploited: Confirmed as exploited in the wild per CISA KEV entry.