Executive brief
A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to achieve heap corruption via a specially crafted HTML page. This flaw can lead to arbitrary code execution and has been observed being exploited in the wild by threat actors.
Affected products
- Google Chrome < 128.0.6613.84
- Microsoft Edge < 128.0.2739.42
- Google V8
Timeline
- 2024-08-21: disclosed: Initial disclosure by Google Chrome team
- 2024-08-21: patched: Chrome version 128.0.6613.84 released to address the vulnerability
- 2024-08-26: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2024-08-30: exploited: Microsoft reports exploitation by North Korean threat actor Citrine Sleet