PT-2024-4241 · Google+5 · Google Chrome+6
Published
2024-05-24
·
Updated
2025-03-19
·
CVE-2024-5830
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 126.0.6478.54
Description
The issue is related to a type confusion vulnerability in the V8 JavaScript engine, allowing a remote attacker to perform an out of bounds memory write via a crafted HTML page. This can lead to remote code execution (RCE) in the renderer sandbox of Chrome by a single visit to a malicious site. The vulnerability is associated with incorrect handling of deprecated maps in the
CreateDataProperty function.Recommendations
For Google Chrome versions prior to 126.0.6478.54, update to version 126.0.6478.54 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious sites to minimize the risk of exploitation. Avoid using the vulnerable V8 JavaScript engine until the issue is resolved. At the moment, there is no other information about additional mitigation measures.
Exploit
Fix
Type Confusion
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
Suse
V8 Javascript Engine