PT-2024-1166 · Google+4 · Google Chrome+5
Published
2024-01-11
·
Updated
2026-05-15
·
CVE-2024-0519
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
The vulnerable software is Google Chrome, specifically the V8 JavaScript engine, which is also used in other Chromium-based browsers such as Microsoft Edge, Brave, and Opera.
The issue is an out-of-bounds memory access vulnerability that can be exploited by attackers to trigger crashes or execute arbitrary code.
The vulnerable versions are Google Chrome prior to 120.0.6099.224.
To fix this issue, users should update their Chrome browser to the latest version, which is 120.0.6099.224/225 for Windows, 120.0.6099.234 for macOS, and 120.0.6099.224 for Linux.
An exploit for this vulnerability exists in the wild, allowing attackers to potentially exploit heap corruption via a crafted HTML page.
It is recommended to update the browser as soon as possible to protect against potential attacks.
#GoogleChrome #V8 #ZeroDay #SecurityUpdate #MicrosoftEdge #CybersecurityNews #InfosecNews #ChromeBrowser #Google #CVE20240519 #CyberSecurity #ZeroDayVulnerability #Chromium #BrowserSecurity
Exploit
Fix
Out of bounds Read
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Google Chrome
Red Os
Suse
V8 Javascript Engine