Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
An attacker prepares a specially crafted HTML page, which when visited by the victim triggers a type confusion error in the V8 engine. Type confusion occurs when the engine treats an object in memory as a different type than it actually is, leading to incorrect heap operations (heap corruption). The error is triggered on the client side with minimal user interaction — simply visiting the malicious page in the browser is sufficient.
An attacker can achieve arbitrary code execution (RCE) in the browser context and potentially escape the browser sandbox, which may lead to complete takeover of the victim's system (high risk of confidentiality, integrity, and availability breach).
Google Chrome must be updated immediately to version 128.0.6613.84 or later. Microsoft Edge users should apply the appropriate patch available from the manufacturer according to references. Due to active exploitation of the vulnerability, the update should be performed immediately.
Google Chrome in versions prior to 128.0.6613.84 and Microsoft Edge based on the same Chromium engine version.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HGoogle Chrome
APPGoogle< 128.0.6613.84Microsoft Edge
APPMicrosoft< 128.0.2739.42
CISA KEV — detailsi
- Vendori
- Google ↗
- Producti
- Chromium V8
- Added to KEVi
- August 26, 2024
- Remediation deadline (US Federal)i
- September 16, 2024(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox
Integer overflow w Skia w Google Chrome — sandbox escape