Skip to content
COOEY

EXPOSURES › CVE-2024-0519

CVE-2024-0519

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-0519 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

Google Chromium V8 engine contains an out-of-bounds memory access vulnerability that allows remote attackers to exploit heap corruption via crafted HTML pages.

This vulnerability affects multiple Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera, posing a significant risk to DIB organizations relying on these browsers for sensitive data. The out-of-bounds memory access can lead to remote code execution, making it critical for vendors to patch immediately and for DIB orgs to verify their browser versions are up to date.

Shame score — While the vulnerability is actively exploited and linked to ransomware, it is a known issue that requires patching rather than a negligent failure or avoidable mistake.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized