PT-2024-4241 · Google+5 · Google Chrome+6

Published

2024-05-24

·

Updated

2025-03-19

·

CVE-2024-5830

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 126.0.6478.54
Description The issue is related to a type confusion vulnerability in the V8 JavaScript engine, allowing a remote attacker to perform an out of bounds memory write via a crafted HTML page. This can lead to remote code execution (RCE) in the renderer sandbox of Chrome by a single visit to a malicious site. The vulnerability is associated with incorrect handling of deprecated maps in the CreateDataProperty function.
Recommendations For Google Chrome versions prior to 126.0.6478.54, update to version 126.0.6478.54 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious sites to minimize the risk of exploitation. Avoid using the vulnerable V8 JavaScript engine until the issue is resolved. At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

Type Confusion

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10294
ALT-PU-2024-14830
ALT-PU-2024-9446
ALT-PU-2025-4366
BDU:2024-04727
CVE-2024-5830
DSA-5710-1
MGASA-2024-0230
OPENSUSE-SU-2024:0204-1
OPENSUSE-SU-2024:0205-1
OPENSUSE-SU-2024:0223-1
OPENSUSE-SU-2024:14122-1
OPENSUSE-SU-2024_0205-1
OPENSUSE-SU-2024_0223-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
Suse
V8 Javascript Engine