8.8
CVSSv3

CVE-2024-4947

Published: 15/05/2024 Updated: 23/05/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Type Confusion in V8 in Google Chrome before 125.0.6422.60 allowed a remote malicious user to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

LTS-120 is being updated in the LTS (Long Term Support) channel, version 12006099312 (Platform Version: 156621090), for most ChromeOS devices Release notes for LTS-120 can be found here Want to know more about Long-term Support? Click hereThis update contains selective Security fixes, including:Chrome Browser Security Fixes3394 ...
 The Chrome team is delighted to announce the promotion of Chrome 125 to the stable channel for Windows, Mac and Linux This will roll out over the coming days/weeksChrome 1250642260 (Linux)  1250642260/61( Windows, Mac) contains a number of fixes and improvements -- a list of changes is available in the log Watch ...

Recent Articles

Google fixes eighth actively exploited Chrome zero-day this year
BleepingComputer • Bill Toulas • 24 May 2024

Google fixes eighth actively exploited Chrome zero-day this year By Bill Toulas May 24, 2024 05:30 AM 0 Google has released a new emergency security update to address the eighth zero-day vulnerability in Chrome browser confirmed to be actively exploited in the wild. The security issue was discovered internally by Google's Clément Lecigne and is tracked as CVE-2024-5274. It is a high-severity 'type confusion' in V8, Chrome's JavaScript engine responsible for executing JS code.  "Google is a...

CISA warns of hackers exploiting Chrome, EoL D-Link bugs
BleepingComputer • Bill Toulas • 19 May 2024

CISA warns of hackers exploiting Chrome, EoL D-Link bugs By Bill Toulas May 19, 2024 10:17 AM 0 The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added three security vulnerabilities to its 'Known Exploited Vulnerabilities' catalog, one impacting Google Chrome and two affecting some D-Link routers. Adding the issues to the KEV catalog serves as a warning to federal agencies and companies that threat actors are leveraging them in attacks and security updates or miti...

Google patches third exploited Chrome zero-day in a week
BleepingComputer • Sergiu Gatlan • 15 May 2024

Google patches third exploited Chrome zero-day in a week By Sergiu Gatlan May 15, 2024 06:36 PM 0 ​Google has released a new emergency Chrome security update to address the third zero-day vulnerability exploited in attacks within a week. "Google is aware that an exploit for CVE-2024-4947 exists in the wild," the search giant said in a security advisory published on Wednesday. The company fixed the zero-day flaw with the release of 125.0.6422.60/.61 for Mac/Windows and 125.0.6422.60 (Linux). Th...

Google fixes third actively exploited Chrome zero-day in a week
BleepingComputer • Sergiu Gatlan • 15 May 2024

Google fixes third actively exploited Chrome zero-day in a week By Sergiu Gatlan May 15, 2024 06:36 PM 2 ​Google has released a new emergency Chrome security update to address the third zero-day vulnerability exploited in attacks within a week. "Google is aware that an exploit for CVE-2024-4947 exists in the wild," the search giant said in a security advisory published on Wednesday. The high-severity zero-day vulnerability (CVE-2024-4947) is caused by a type confusion weakness in the Chrome V8...