CRITICAL KEV
chromium-browser: Type confusion in V8 in Google Chrome allows a remote attacker to exploit heap corruption via a crafted HTML page
Published Aug 21, 2024 ·Due Sep 16, 2024
9.6
CRITICALCVSS 3.1
EPSS 21.10%
Description
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected products
-
- Version 128.0.6613.84StatusaffectedConstraints<128.0.6613.84
- Version
-
- Version 0StatusaffectedConstraints<128.0.6613.84
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Chromium is not shipped in any supported Red Hat offerings.
Red Hat mitigation
Until updated packages are released for Fedora and EPEL, consider temporarily swapping to an alternative web browser such as Firefox or severely restricting activity to sites you know well and trust.
Weaknesses (1)
References (9)
- https://access.redhat.com/security/cve/CVE-2024-7971 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2307092 Issue Tracking
- https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html Release Notes
- https://issues.chromium.org/issues/360700873 Permissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2024-7971
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7971 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2024-7971
- https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/ ExploitPatchThird Party AdvisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-7971 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2307092 | Issue Tracking | |
| https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html | Release Notes | |
| https://issues.chromium.org/issues/360700873 | Permissions Required | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-7971 | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7971 | government-resourceUS Government Resource | |
| https://www.cve.org/CVERecord?id=CVE-2024-7971 | ||
| https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/ | ExploitPatchThird Party AdvisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Aug 21, 2024
Updated Oct 21, 2025
Reserved Aug 19, 2024
Link CVE-2024-7971
CISA Vulnrichment
Updated Aug 26, 2024