PT-2024-4025 · Google+5 · Google Chrome+5
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 125.0.6422.112
Description
A type confusion issue exists in the V8 JavaScript engine. This flaw allows a remote attacker to execute arbitrary code within a sandbox by inducing the user to visit a specially crafted HTML page. Type confusion occurs when a program accesses a resource using a different type than the one it was originally created with, leading to memory corruption or unexpected behavior. There are reports of this issue being exploited in the wild.
Recommendations
Update to version 125.0.6422.112 or later.
Exploit
Fix
DoS
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
Suse