CVE-2024-7974 is a medium-severity vulnerability in Google Chrome, specifically affecting versions prior to 128.0.6613.84. It stems from insufficient data validation within the V8 API, allowing a remote attacker to potentially trigger heap corruption through a specially crafted Chrome Extension. With a CVSS score of 8.8 (HIGH), successful exploitation could lead to high impact on confidentiality, integrity, and availability, requiring user interaction (UI:R) but with low attack complexity (AC:L). Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 128.0.6613.84CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 128.0.6613.84, < 128.0.6613.84CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.