Junglewise Threat Intelligence

CVE-2024-4761: Google Chromium V8 Out-of-Bounds Memory Write Vulnerability

CVE-2024-4761 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-05-16

Technologies: Google Chromium V8, Google Chrome, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

Google Chromium V8 engine contains an out-of-bounds memory write vulnerability. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution.

Affected products

  • Google Chrome prior to 124.0.6367.207
  • Microsoft Edge
  • Opera Software Opera
  • Fedora Project Fedora 38, 39, 40

Timeline

  • 2024-05-13: patched: Stable channel update for desktop released by Google.
  • 2024-05-16: disclosed: Vulnerability published.
  • 2024-05-16: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
  • 2024-05-16: exploited: Reported as exploited in the wild.

Related threats