CVE-2024-4947 - Google Chromium V8 Type Confusion Vulnerability
Project:Google
Product:Chromium V8
Date Added:2024-05-20Due Date:2024-06-10
Vulnerability Name
Google Chromium V8 Type Confusion Vulnerability
Description
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html
https://nvd.nist.gov/vuln/detail/CVE-2024-4947
Related News Articles
Exploited: Cisco, SharePoint, Chrome vulnerabilitiesOctober 25, 2024
Lazarus Group Exploits Google Chrome Vulnerability to Control Infected DevicesOctober 24, 2024
Lazarus hackers used fake DeFi game to exploit Google Chrome zero-dayOctober 24, 2024
North Korean Hackers Deploy FudModule Rootkit via Chrome Zero-Day ExploitAugust 31, 2024
Google Warns of CVE-2024-7965 Chrome Security Flaw Under Active ExploitationAugust 27, 2024