Junglewise Threat Intelligence

CVE-2024-4947: Google Chromium V8 Type Confusion Vulnerability

CVE-2024-4947 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2024-05-20

Technologies: Google Chromium V8, Google Chrome. Vendors: Google.

Executive brief

A type confusion vulnerability in the V8 engine of Google Chromium allows a remote attacker to execute arbitrary code within a sandbox. Exploitation is achieved via a specially crafted HTML page and has been observed in the wild.

Affected products

  • Google Chrome prior to 125.0.6422.60
  • Google V8 prior to 125.0.6422.60
  • Fedora Project Fedora 38, 39, 40

Timeline

  • 2024-05-15: patched: Stable channel update for desktop released.
  • 2024-05-20: disclosed: CVE published and added to CISA KEV catalog.
  • 2024-05-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
  • 2024-05-20: exploited: Reported as exploited in the wild.

Related threats