PT-2024-1166 · Google+4 · Google Chrome+5

Published

2024-01-11

·

Updated

2026-05-15

·

CVE-2024-0519

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
The vulnerable software is Google Chrome, specifically the V8 JavaScript engine, which is also used in other Chromium-based browsers such as Microsoft Edge, Brave, and Opera. The issue is an out-of-bounds memory access vulnerability that can be exploited by attackers to trigger crashes or execute arbitrary code. The vulnerable versions are Google Chrome prior to 120.0.6099.224. To fix this issue, users should update their Chrome browser to the latest version, which is 120.0.6099.224/225 for Windows, 120.0.6099.234 for macOS, and 120.0.6099.224 for Linux. An exploit for this vulnerability exists in the wild, allowing attackers to potentially exploit heap corruption via a crafted HTML page. It is recommended to update the browser as soon as possible to protect against potential attacks. #GoogleChrome #V8 #ZeroDay #SecurityUpdate #MicrosoftEdge #CybersecurityNews #InfosecNews #ChromeBrowser #Google #CVE20240519 #CyberSecurity #ZeroDayVulnerability #Chromium #BrowserSecurity

Exploit

Fix

Out of bounds Read

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-10294
ALT-PU-2024-14286
ALT-PU-2024-14830
ALT-PU-2024-2062
ALT-PU-2024-3216
ALT-PU-2024-4232
ALT-PU-2024-4260
ALT-PU-2024-4381
ALT-PU-2024-6148
BDU:2024-00492
CVE-2024-0519
DSA-5602-1
MGASA-2024-0017
OPENSUSE-SU-2024:0025-1
OPENSUSE-SU-2024:0033-1
OPENSUSE-SU-2024:13591-1
OPENSUSE-SU-2024:13603-1
OPENSUSE-SU-2024:14001-1
OPENSUSE-SU-2024_0033-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Red Os
Suse
V8 Javascript Engine