CyberzSOC

Publication detail
← Back to advisories & guidance

2024-088: Chrome ZeroDay Vulnerabilities ↗ source

August 27, 2024 CERT-EU Advisory

Summary

The flaw, which has been actively exploited in the wild, is rooted in a type confusion issue within Chrome’s V8 JavaScript engine. This vulnerability allows attackers to potentially execute arbitrary code on affected [New] On August 26, Google announced that it patched the tenth zero-day vulnerability in Chrome. This vulnerability is also reported as being exploited [1]. [Updated] The vulnerability CVE-2024-7971, with a CVSS score of 8.8, is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome. Type confusion errors occur when a resource, such as a pointer or object, is allocated as one type but later accessed using a different, incompatible type. This discrepancy can lead to logical errors, including memory corruption, which attackers can exploit to execute arbitrary code or cause the browser to crash.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-7965 8.8 High Google Chromium V8 Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a …
CVE-2024-7971 8.8 High Google Chromium V8 Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vul…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.