PT-2024-3653 · Google+4 · V8 Javascript Engine+5

Boris Larin

+3

·

Published

2024-05-15

·

Updated

2025-09-01

·

CVE-2024-4947

CVSS v3.1

9.6

Critical

AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 125.0.6422.60 Chromium versions prior to 126.0.6478.182-alt0.c10.1 Chromium-Gost versions prior to 125.0.6422.112-alt0.c10.1 Yandex-browser-stable version 24.4.3.1111-alt1 Chromium versions prior to 125.0.6422.60-1~deb12u1 (Debian bookworm)
Description A type confusion vulnerability exists in the V8 JavaScript and WebAssembly engine in Google Chrome and Chromium-based browsers. This flaw could allow a remote attacker to execute arbitrary code within a sandbox via a crafted HTML page. The vulnerability has been actively exploited in attacks, including by the Lazarus APT group who used a malicious game to deliver malware. Exploitation of this vulnerability can lead to remote code execution and potential unauthorized access or control of affected systems.
Recommendations Update Google Chrome to version 125.0.6422.60 or later. Update Chromium to version 126.0.6478.182-alt0.c10.1 or later. Update Chromium-Gost to version 125.0.6422.112-alt0.c10.1 or later. Update Yandex-browser-stable to version 24.4.3.1111-alt1. Update Chromium to version 125.0.6422.60-1~deb12u1 or later (Debian bookworm).

Exploit

Fix

RCE

Type Confusion

Improperly Implemented Security Check for Standard

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10294
ALT-PU-2024-11865
ALT-PU-2024-14286
ALT-PU-2024-14830
ALT-PU-2024-8361
ALT-PU-2024-9404
ALT-PU-2024-9406
ALT-PU-2024-9716
ALT-PU-2024-9718
BDU:2024-03978
BDU:2024-08627
BDU:2024-08628
BDU:2024-08629
CVE-2024-4947
DSA-5694-1
MGASA-2024-0190
OPENSUSE-SU-2024:13982-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
V8 Javascript Engine