CVE-2024-7971

Published Aug 21, 2024

Last updated 2 months ago

Overview

Description
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.6
Impact score
6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Google Chromium V8 Type Confusion Vulnerability
Exploit added on
Aug 26, 2024
Exploit action due
Sep 16, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

chrome-cve-admin@google.com
CWE-843
nvd@nist.gov
CWE-843
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-843

Social media

Hype score
Not currently trending
  1. Top 5 Trending CVEs: 1 - CVE-2024-50379 2 - CVE-2024-38200 3 - CVE-2024-12856 4 - CVE-2023-48788 5 - CVE-2024-7971 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    30 Dec 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Version 124.0.6327.3 is significantly outdated. https://t.co/zy62zi4JHz CVE-2024-4058: A critical type confusion vulnerability in ANGLE (WebGL component) that could allow heap corruption exploitation through crafted HTML pages. CVE-2024-7971: A high-severity type confusion in…

    @gnukeith

    24 Dec 2024

    1226 Impressions

    3 Retweets

    33 Likes

    4 Bookmarks

    2 Replies

    1 Quote

  3. North Korean hackers exploit Chrome zero-day to deploy rootkit North Korean hackers have exploited a recently patched Google Chrome zero-day (CVE-2024-7971) to deploy the FudModule rootkit after gaining SYSTEM privileges using a Windows Kernel exploit.... https://t.co/IcYuqpf5zq

    @SecurityAid

    13 Dec 2024

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔴 #Google #Chrome, Type Confusion Vulnerability, #CVE-2024-7971 (Critical) - Critical https://t.co/aIw2VP7zR2

    @dailycve

    27 Nov 2024

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Actively exploited CVE : CVE-2024-7971

    @transilienceai

    24 Nov 2024

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🚨 Zero-Day Alert! 🚨North Korean threat actor Citrine Sleet is back, exploiting a zero-day vulnerability (CVE-2024-7971) in Chromium, targeting #Cryptocurrency institutions.💰 Book your #Demo now: https://t.co/lGRc2vih4Q https://t.co/yO6eYeNAIK

    @Akitra_Inc

    21 Oct 2024

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations