CVE-2024-5274
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- May 23, 2024
- Published Date
- May 28, 2024
- Last Updated
- February 13, 2025
- Vendor
- Product
- Chrome
- Description
- Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS Scores
CVSS v3.1
9.6 - CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html
https://issues.chromium.org/issues/341663589
https://lists.fedoraproject.org/archives/list/[email protected]/message/T6IBUYVPD4MIFQNNYBGAPI5MOECWXXOB/
https://lists.fedoraproject.org/archives/list/[email protected]/message/AVC3FNI7HZLVSRIFBVUSBHI233DZYBKP/
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2024-05-28 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
mistymntncop/CVE-2024-5274
Type: github • Created: 2024-08-29 11:58:25 UTC • Stars: 80
Alchemist3dot14/CVE-2024-5274-Detection
Type: github • Created: 2024-07-10 02:15:56 UTC • Stars: 4
Guardian Code: A Script to Uncover CVE-2024-5274 Vulnerabilities