Executive brief
An inappropriate implementation in the V8 engine in Google Chrome allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability has been observed being exploited in the wild and affects Chromium-based browsers.
Affected products
- Google Chrome prior to 128.0.6613.84
- Microsoft Edge Chromium prior to 128.0.2739.42
- Google V8
Timeline
- 2024-08-21: disclosed: Initial disclosure by Chrome and NVD publication.
- 2024-08-21: patched: Chrome release 128.0.6613.84 fixes the issue.
- 2024-08-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2024-08-28: exploited: Reported as exploited in the wild.