Skip to content
COOEY

EXPOSURES › CVE-2024-4761

CVE-2024-4761

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-4761 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

Google Chromium V8 engine contains an out-of-bounds memory write vulnerability exploitable via crafted HTML pages.

This vulnerability affects multiple Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera, posing a significant risk to DIB organizations relying on these browsers for sensitive data handling. The vulnerability is actively exploited in the KEV list, indicating widespread impact and requiring immediate patching to prevent potential remote code execution.

Shame score — While not a zero-day, the active exploitation status and broad vendor impact warrant moderate embarrassment for Google's security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized