chromereleases.googleblog.com
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_13.html CVE-2024-4761
HIGHCISA KEV
Google Chromium V8 Out-of-Bounds Memory Write Vulnerability
Record summary
CVE-2024-4761 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2024-4761 in KEV.
Description
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · May 16, 2024 · CISA
- VulnCheck KEV
- Listed · May 9, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / Chrome | CVE List | 124.0.6367.207 to < 124.0.6367.207 | affected |
Chromium V8Browse Google / Chromium V8 | CISA | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubmichredteam/CVE-2024-4761Repository PoCby michredteamStars: 4Not analyzed3 files
References
7issues.chromium.org
https://issues.chromium.org/issues/339458194 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NTSN22LNYXMWHVTYNOYQVOY7VDZFHENQ lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WSUWM73ZCXTN62AT2REYQDD5ZKPFMDZD nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-4761 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4761