8.8
CVSSv3

CVE-2024-0519

Published: 16/01/2024 Updated: 22/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Out of bounds memory access in V8 in Google Chrome before 120.0.6099.224 allowed a remote malicious user to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

The Stable channel has been updated to 12006099234 for Mac and 12006099224 for Linux and 12006099224/225 to Windows which will roll out over the coming days/weeks A full list of changes in this build is available in the LogThe Extended Stable channel has been updated to 12006099234 for Mac and 12006099225 for Windows which will rol ...
LTS-114 is being updated in the LTS channel to 11405735347 (Platform Version: 15437870) for most ChromeOS devices Want to know more about Long Term Support? Click hereThis update contains multiple Security fixes, including:1500921  High  CVE-2023-6706 Use after free in FedCM1502102  High ...

Github Repositories

Execute arbitrary code on the victim’s device, compromising data security and system integrity in Chrome 120.0.6099

CVE-2024-0519-Chrome-exploit Execute arbitrary code on the victim’s device, compromising data security and system integrity in Chrome 12006099 🔥 CVSS: 88/10 Description CVE-2024-0519 is a high-severity out-of-bounds memory access vulnerability in the V8 JavaScript and WebAssembly engines This script is an exploit the vulnerability to trigger a crash Exploit detail

Execute arbitrary code on the victim’s device, compromising data security and system integrity in Chrome 120.0.6099

CVE-2024-0519-Chrome-exploit Execute arbitrary code on the victim’s device, compromising data security and system integrity in Chrome 12006099 🔥 CVSS: 88/10 Description CVE-2024-0519 is a high-severity out-of-bounds memory access vulnerability in the V8 JavaScript and WebAssembly engines This script is an exploit the vulnerability to trigger a crash Exploit detail

Recent Articles

Google fixes third actively exploited Chrome zero-day in a week
BleepingComputer • Sergiu Gatlan • 15 May 2024

Google fixes third actively exploited Chrome zero-day in a week By Sergiu Gatlan May 15, 2024 06:36 PM 2 ​Google has released a new emergency Chrome security update to address the third zero-day vulnerability exploited in attacks within a week. "Google is aware that an exploit for CVE-2024-4947 exists in the wild," the search giant said in a security advisory published on Wednesday. The high-severity zero-day vulnerability (CVE-2024-4947) is caused by a type confusion weakness in the Chrome V8...

Google patches third exploited Chrome zero-day in a week
BleepingComputer • Sergiu Gatlan • 15 May 2024

Google patches third exploited Chrome zero-day in a week By Sergiu Gatlan May 15, 2024 06:36 PM 0 ​Google has released a new emergency Chrome security update to address the third zero-day vulnerability exploited in attacks within a week. "Google is aware that an exploit for CVE-2024-4947 exists in the wild," the search giant said in a security advisory published on Wednesday. The company fixed the zero-day flaw with the release of 125.0.6422.60/.61 for Mac/Windows and 125.0.6422.60 (Linux). Th...

Google Chrome emergency update fixes 6th zero-day exploited in 2024
BleepingComputer • Bill Toulas • 14 May 2024

Google Chrome emergency update fixes 6th zero-day exploited in 2024 By Bill Toulas May 14, 2024 04:10 AM 0 Google has released emergency security updates for the Chrome browser to address a high-severity zero-day vulnerability tagged as exploited in attacks. This fix comes only three days after Google addressed another zero-day vulnerability in Chrome, CVE-2024-4671, caused by a use-after-free weakness in the Visuals component. The latest bug is tracked as CVE-2024-4761. It is an out-of-bounds w...

Google fixes fifth Chrome zero-day exploited in attacks this year
BleepingComputer • Bill Toulas • 10 May 2024

Google fixes fifth Chrome zero-day exploited in attacks this year By Bill Toulas May 10, 2024 04:08 AM 0 ​Google has released a security update for the Chrome browser to fix the fifth zero-day vulnerability exploited in the wild since the start of the year. The high-severity issue tracked as CVE-2024-4671 is a “user after free” vulnerability in the Visuals component that handles the rendering and display of content on the browser. CVE-2024-4671 was discovered and reported to Google by an a...

Google fixes one more Chrome zero-day exploited at Pwn2Own
BleepingComputer • Sergiu Gatlan • 03 Apr 2024

Google fixes one more Chrome zero-day exploited at Pwn2Own By Sergiu Gatlan April 3, 2024 12:39 PM 0 Google has fixed another zero-day vulnerability in the Chrome browser, which was exploited by security researchers during the Pwn2Own hacking contest last month. Tracked as CVE-2024-3159, this high-severity security flaw is caused by an out-of-bounds read weakness in the Chrome V8 JavaScript engine. Remote attackers can exploit the vulnerability using crafted HTML pages to gain access to data bey...

Google fixes Chrome zero-days exploited at Pwn2Own 2024
BleepingComputer • Sergiu Gatlan • 27 Mar 2024

Google fixes Chrome zero-days exploited at Pwn2Own 2024 By Sergiu Gatlan March 27, 2024 02:44 PM 0 Google fixed seven security vulnerabilities in the Chrome web browser on Tuesday, including two zero-days exploited during the Pwn2Own Vancouver 2024 hacking competition. The first (tracked as CVE-2024-2887) is a high-severity type confusion weakness in the WebAssembly (Wasm) open standard. Manfred Paul demoed this vulnerability on the first day of Pwn2Own as part of a double-tap remote code execut...