CVE-2024-7965 is a high-severity inappropriate implementation vulnerability in the V8 JavaScript engine, affecting Google Chrome and Microsoft Edge (Chromium-based browsers). This flaw allows a remote attacker to achieve heap corruption by tricking a user into visiting a specially crafted HTML page. With a CVSS score of 8.8, it presents a high risk due to its network-based attack vector, low attack complexity, and potential for high impact on confidentiality, integrity, and availability. Notably, this vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 128.0.6613.84CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 128.0.2739.42CPE matchmatch criteria | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* | ||
>= 128.0.6613.84, < 128.0.6613.84CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.