Executive brief
A type confusion vulnerability in the V8 engine of Google Chromium allows a remote attacker to execute arbitrary code within a sandbox. Exploitation is achieved via a specially crafted HTML page and has been observed in the wild.
Affected products
- Google Chrome prior to 125.0.6422.60
- Google V8 prior to 125.0.6422.60
- Fedora Project Fedora 38, 39, 40
Timeline
- 2024-05-15: patched: Stable channel update for desktop released.
- 2024-05-20: disclosed: CVE published and added to CISA KEV catalog.
- 2024-05-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- 2024-05-20: exploited: Reported as exploited in the wild.