CISA Known Exploited Vulnerability (KEV)
Google Chromium V8 Type Confusion Vulnerability
August 26, 2024
September 16, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
References
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-843 |
Access of Resource Using Incompatible Type (‘Type Confusion’) |