Junglewise Threat Intelligence

CVE-2024-7965: Google Chromium V8 Inappropriate Implementation Vulnerability

CVE-2024-7965 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-08-28

Technologies: Google Chromium V8, Microsoft Edge Chromium, Google Chrome. Vendors: Google, Microsoft.

Executive brief

An inappropriate implementation in the V8 engine in Google Chrome allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability has been observed being exploited in the wild and affects Chromium-based browsers.

Affected products

  • Google Chrome prior to 128.0.6613.84
  • Microsoft Edge Chromium prior to 128.0.2739.42
  • Google V8

Timeline

  • 2024-08-21: disclosed: Initial disclosure by Chrome and NVD publication.
  • 2024-08-21: patched: Chrome release 128.0.6613.84 fixes the issue.
  • 2024-08-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2024-08-28: exploited: Reported as exploited in the wild.

Related threats