CVE-2024-2884 is an out-of-bounds read vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 121.0.6167.139. This medium-severity flaw, with a CVSS score of 6.5, allows a remote attacker to potentially access out-of-bounds memory by enticing a user to visit a specially crafted HTML page. While there is no evidence of active exploitation, public exploit code, or significant community discussion, users are advised to update Chrome to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 121.0.6167.139CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 121.0.6167.139, < 121.0.6167.139CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.