CVE-2024-5274 is a high-severity type confusion vulnerability in Google Chrome's V8 JavaScript engine, affecting Chrome and Fedora versions prior to 125.0.6422.112. This flaw allows a remote attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a crafted HTML page. With a CVSS score of 9.6 (CRITICAL), it poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Notably, this vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered substantial community discussion and media coverage, including reports of Russian APT groups leveraging similar exploits.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 125.0.6422.112CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* | ||
>= 125.0.6422.112, < 125.0.6422.112CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.