Junglewise Threat Intelligence

CVE-2024-0519: Google Chromium V8 Out-of-Bounds Memory Access Vulnerability

CVE-2024-0519 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-01-17

Technologies: Google Chrome, Google Chromium V8, Fedora Project Space Fedora. Vendors: Google.

Executive brief

An out-of-bounds memory access vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially exploit heap corruption via a specially crafted HTML page. This flaw can lead to unauthorized memory access and is known to be exploited in the wild.

Affected products

  • Google Chrome prior to 120.0.6099.224
  • Couchbase Couchbase Server up to (excluding) 7.2.5
  • Fedora Project Space Fedora 38, 39

Timeline

  • 2024-01-16: patched: Google released Chrome version 120.0.6099.224 to address the vulnerability.
  • 2024-01-17: disclosed
  • 2024-01-17: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats