CVE-2024-5274

CRITICAL KEV

Google Chrome < 125.0.6422.112 - Remote Code Execution via V8 Type Confusion

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-5274 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 28, 2024. EIP tracks 2 public exploits from researchers including mistymntncop, Alchemist3dot14.

AI-analyzed exploit summary This is a working exploit PoC for CVE-2024-5274, targeting a V8 JavaScript engine vulnerability involving a bytecode mismatch and out-of-bounds (OOB) read/write primitives. The exploit leverages a contradiction in variable state flags to achieve arbitrary memory manipulation.

Description

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Exploits (2)

nomisec WORKING POC 81 stars
by mistymntncop · client-side
https://github.com/mistymntncop/CVE-2024-5274

This is a working exploit PoC for CVE-2024-5274, targeting a V8 JavaScript engine vulnerability involving a bytecode mismatch and out-of-bounds (OOB) read/write primitives. The exploit leverages a contradiction in variable state flags to achieve arbitrary memory manipulation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: V8 JavaScript Engine (specific commit bf4298bafd04910c2cd634738ae73f4a4151b47d)
No auth needed
Prerequisites: V8 JavaScript engine built from specific commit · Ability to execute arbitrary JavaScript in the target environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 3 stars
by Alchemist3dot14 · poc
https://github.com/Alchemist3dot14/CVE-2024-5274-Detection

This repository contains a Python script to detect and initiate updates for Google Chrome to mitigate CVE-2024-5274. It checks the current Chrome version and prompts an update if the version is outdated.

Classification
Scanner 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Google Chrome versions prior to 125.0.6422.112/.113
No auth needed
Prerequisites: Google Chrome installed on the system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.6
EPSS 0.1002
EPSS Percentile 95.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2024-05-28
VulnCheck KEV 2024-05-20
InTheWild.io 2024-05-20
ENISA EUVD EUVD-2024-46510
CWE
CWE-843
Status published
Products (3)
fedoraproject/fedora 39
fedoraproject/fedora 40
google/chrome < 125.0.6422.112
Published May 28, 2024
KEV Added May 28, 2024
Tracked Since Feb 18, 2026