CVE-2024-4947 is a critical type confusion vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 125.0.6422.60, as well as Fedora Project's Chrome and Fedora distributions. This flaw allows a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. With a CVSS score of 9.6 (CRITICAL), it presents a high risk due to its network-based attack vector, low attack complexity, and severe potential for confidentiality, integrity, and availability compromise. Notably, this vulnerability is actively exploited in the wild, with evidence suggesting the Lazarus hacking group has leveraged it through fake DeFi games, garnering significant community discussion and media attention despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 125.0.6422.60CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* | ||
>= 125.0.6422.60, < 125.0.6422.60CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.