Executive brief
A type confusion vulnerability exists in the Google Chromium V8 engine. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution within the browser sandbox.
Affected products
- Google Chrome prior to 125.0.6422.112
- Microsoft Edge
- Opera Opera
- Fedora Project Fedora 39
- Fedora Project Fedora 40
Timeline
- 2024-05-23: patched: Stable channel update for desktop released (125.0.6422.112)
- 2024-05-28: disclosed: Initial NVD publication and CISA KEV addition
- 2024-05-28: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2024-05-28: exploited: Confirmed as exploited in the wild per CISA and Google reports