PT-2024-6341 · Google+4 · Google Chrome+5
Ganjiang Zhou
+1
·
Published
2024-08-15
·
Updated
2025-03-19
·
CVE-2024-8905
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 129.0.6668.58
Description
The issue is related to an inappropriate implementation in the V8 engine of Google Chrome, which could allow a remote attacker to potentially exploit stack corruption via a crafted HTML page. This could impact the confidentiality, integrity, and availability of protected information. The vulnerability is associated with a buffer overflow in memory due to incorrectly implemented security checks for standard elements.
Recommendations
For Google Chrome versions prior to 129.0.6668.58, update to version 129.0.6668.58 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted HTML pages that could exploit the stack corruption vulnerability in the V8 engine. Restrict access to sensitive information and ensure that only trusted sources are used to minimize the risk of exploitation.
Exploit
Fix
Memory Corruption
Improperly Implemented Security Check for Standard
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
V8 Engine