HIGH
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page
Published Sep 24, 2024
8.8
HIGHCVSS 3.1
EPSS 0.51%
Description
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Affected products
-
Affected
- ≥ 129.0.6668.70, < 129.0.6668.70
-
Affected
- ≥ 0, < 129.0.6668.70
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_24.html Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49743 Advisory
- https://issues.chromium.org/issues/363538434 ExploitIssue Tracking
| Link | Providers | Tags |
|---|---|---|
| https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_24.html | Release Notes | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49743 | Advisory | |
| https://issues.chromium.org/issues/363538434 | ExploitIssue Tracking |
Change history (3)
- CISA ADP
SSVC technical impact
changed from partial to totalpartial → total
- CISA ADP
SSVC technical impact
changed from total to partialtotal → partial
- CISA ADP
SSVC technical impact
changed from partial to totalpartial → total
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Sep 24, 2024
Updated Sep 26, 2024
Reserved Sep 23, 2024
Link CVE-2024-9121
CISA Vulnrichment
Updated Sep 25, 2024
Red Hat
No data
GitHub
No data