CyberzSOC

Publication detail
← Back to advisories & guidance

2024-044: Zero-day Vulnerability in Chrome ↗ source

May 16, 2024 CERT-EU Advisory

Summary

It has been reported that this vulnerability is being actively exploited [1]. This is the seventh zero-day vulnerability fixed by Google this year. Google Chrome prior to version 125.0.6422.60/.61 for Windows and Mac, 125.0.6422.60 for Linux are impacted [1]. Other Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi are also affected. It is recommended updating Google Chrome browsers to the latest version.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-4671 9.6 Critical Google Chromium Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. Thi…
CVE-2024-4947 9.6 Critical Google Chromium V8 Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.
CVE-2024-0519 8.8 High Google Chromium V8 Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption …
CVE-2024-3159 8.8 High Google Chrome Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HT…
CVE-2024-4761 8.3 High Google Chromium V8 Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect m…
CVE-2024-2887 8.1 High Google Chrome Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (C…
CVE-2024-2886 7.5 High Google Chrome Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.