CVE-2024-7969 is a high-severity type confusion vulnerability in the V8 JavaScript engine, affecting Google Chrome prior to version 128.0.6613.113. A remote attacker can exploit this flaw by enticing a user to visit a crafted HTML page, potentially leading to heap corruption. The vulnerability carries a CVSS score of 8.8, indicating high impact on confidentiality, integrity, and availability, and requires user interaction. While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 128.0.6613.84CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 128.0.6613.113, < 128.0.6613.113CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.