Skip to content
COOEY

EXPOSURES › CVE-2024-7965

CVE-2024-7965

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-08-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-7965 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildransomware

Google Chromium V8 allows remote attackers to exploit heap corruption via crafted HTML pages, affecting all Chromium-based browsers.

This vulnerability enables remote code execution through heap corruption in the V8 engine, impacting Google Chrome, Microsoft Edge, and Opera. DIB organizations must patch immediately to prevent ransomware or data exfiltration via compromised browser sessions.

Shame score — While the vulnerability is high severity and actively exploited, it is a known implementation flaw rather than a vendor-specific negligence or supply-chain failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized