CVE-2024-4059 is an out-of-bounds read vulnerability in the V8 API of Google Chrome, affecting versions prior to 124.0.6367.78, as well as Fedora's Chrome and Fedora distributions. This high-severity flaw allows a remote attacker to leak cross-site data by enticing a user to visit a crafted HTML page. While the CVSS score is 6.5 (Medium), indicating a network-based attack with low complexity but requiring user interaction, there is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog. Despite limited community discussion, the vulnerability has garnered some media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 124.0.6367.78CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* | ||
>= 124.0.6367.78, < 124.0.6367.78CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.