CVE-2024-7971 is a critical type confusion vulnerability in the V8 JavaScript engine within Google Chrome and Microsoft Edge, allowing remote attackers to achieve heap corruption via crafted HTML. With a CVSS score of 9.6, it presents a high severity risk, requiring user interaction (visiting a malicious page) but offering complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, notably by North Korean threat actors, despite no public exploit code being readily available on platforms like Metasploit or ExploitDB. The high number of community discussions and media coverage underscore its significant impact and active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 128.0.6613.84CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 128.0.2739.42CPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* | ||
>= 128.0.6613.84, < 128.0.6613.84CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.