PT-2024-5817 · Google+5 · V8 Javascript Engine+6
Published
2024-08-21
·
Updated
2026-04-05
·
CVE-2024-7971
CVSS v3.1
10
Critical
| AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
The vulnerable software is Google Chrome, specifically the V8 JavaScript engine. The vulnerability is a type confusion issue that can be exploited to execute arbitrary code on affected systems.
The vulnerable versions are prior to 128.0.6613.84.
To exploit this vulnerability, an attacker can use a crafted HTML page to corrupt the heap and execute malicious code.
It is recommended to update Google Chrome to the latest version, 128.0.6613.84 or later, to patch this vulnerability.
North Korean hackers, known as Citrine Sleet, have been exploiting this vulnerability to deploy the FudModule rootkit and steal cryptocurrency.
#GoogleChrome #V8JavaScriptEngine #TypeConfusionVulnerability #RemoteCodeExecution #CyberSecurity #ZeroDayExploit #ChromeUpdate #PatchNow #CyberAttack #InfoSec #VulnerabilityManagement #Exploit #CVE
Exploit
Fix
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
Suse
V8 Javascript Engine