CVE-2024-7971

CRITICAL CISA KEV EPSS 97.0%
Published Aug 21, 20241y ago · Modified Jun 17, 20261w ago
9.6 CVSS 3.1
Critical
Find Similar
Published Aug 21, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
KEV Listed Aug 26, 2024 1y ago
KEV Due Sep 16, 2024 652d overdue

Description

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS Details

Base Score
9.6
Exploitability
2.8
Impact
6.0
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality High
Integrity High
Availability High

Threat Intelligence

CISA Known Exploited Overdue 652d
Added
Aug 26, 2024
Due
Sep 16, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

EPSS Exploit Probability
97.0% percentile
Exploit & Patch Status
Actively Exploited (KEV)
Patch Available

Weaknesses 1

CWE-843

Affected Products 2

VendorProductVersionRange
googlechrome* <128.0.6613.84
microsoftedge* <128.0.2739.42

References 4

  • chromereleases.googleblog.com https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html
    Release Notes
  • issues.chromium.org https://issues.chromium.org/issues/360700873
    Permissions Required
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7971
    US Government Resource
  • microsoft.com https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/
    ExploitPatchThird Party AdvisoryVendor Advisory

Remediation

  • microsoft.com https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/
    ExploitPatchThird Party AdvisoryVendor Advisory