CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2024-5274

CVSS 9.6v3.1pub. 2024-05-28upd. 2025-10-24

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🤖 AI Analysis
How it works

The type confusion error (CWE-843) in the V8 engine involves the JavaScript engine incorrectly interpreting the type of an object in memory, treating it as a different type than it actually is. An attacker can craft an HTML page containing appropriate JavaScript code that forces this incorrect interpretation. As a result, it is possible to execute arbitrary code in the context of the browser rendering process, even with the sandbox mechanism active.

Impact

An attacker can execute arbitrary code (RCE) within the browser sandbox, which may lead to violations of confidentiality, integrity, and availability of data processed by the browser. Combined with a separate vulnerability enabling sandbox escape, it is possible to take control of the victim's system.

Mitigation & patch

Google Chrome should be updated to version 125.0.6422.112 or newer. Fedora users should apply package updates published by the Fedora Project according to references. It is also recommended to enable automatic browser updates.

Who is affected

Google Chrome in versions earlier than 125.0.6422.112 and Google Chrome packages available in Fedora Linux distributions (according to Fedora Project package lists).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Fedora Project Fedora

    OS
    Fedoraproject
    3940
  • Google Chrome

    APP
    Google
    < 125.0.6422.112

CISA KEV — detailsi

Vendori
Google
Producti
Chromium V8
Added to KEVi
May 28, 2024
Remediation deadline (US Federal)i
June 18, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 18 czerwca 2024
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2024-7971CRITICAL9.6⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit

CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)

CVE-2024-4671CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox