Junglewise Threat Intelligence

CVE-2024-5274: Google Chromium V8 Type Confusion Vulnerability

CVE-2024-5274 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2024-05-28

Technologies: Google Chromium V8, Microsoft Edge, Google Chrome. Vendors: Google, Opera, Microsoft.

Executive brief

A type confusion vulnerability exists in the Google Chromium V8 engine. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution within the browser sandbox.

Affected products

  • Google Chrome prior to 125.0.6422.112
  • Microsoft Edge
  • Opera Opera
  • Fedora Project Fedora 39
  • Fedora Project Fedora 40

Timeline

  • 2024-05-23: patched: Stable channel update for desktop released (125.0.6422.112)
  • 2024-05-28: disclosed: Initial NVD publication and CISA KEV addition
  • 2024-05-28: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2024-05-28: exploited: Confirmed as exploited in the wild per CISA and Google reports

Related threats