CISA Known Exploited Vulnerability (KEV)
Google Chromium V8 Type Confusion Vulnerability
May 28, 2024
June 18, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
References
- https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html
- https://issues.chromium.org/issues/341663589
- https://lists.fedoraproject.org/archives/list/[email protected]/message/AVC3FNI7HZLVSRIFBVUSBHI233DZYBKP/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/T6IBUYVPD4MIFQNNYBGAPI5MOECWXXOB/
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-843 |
Access of Resource Using Incompatible Type (‘Type Confusion’) |