Executive brief
Google Chromium V8 engine contains an out-of-bounds memory write vulnerability. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution.
Affected products
- Google Chrome prior to 124.0.6367.207
- Microsoft Edge
- Opera Software Opera
- Fedora Project Fedora 38, 39, 40
Timeline
- 2024-05-13: patched: Stable channel update for desktop released by Google.
- 2024-05-16: disclosed: Vulnerability published.
- 2024-05-16: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- 2024-05-16: exploited: Reported as exploited in the wild.