CVE-2024-5274: Google Chromium V8 Type Confusion Vulnerability
Chromium: CVE-2024-5274 Type Confusion in V8
Other sources
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
— CISA
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2024-5274 exists in the wild.
— Microsoft
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 125.0.6422.112 - Upgrade
Upgrade
Google Chrome/Chromium (V8)to a version that resolves this vulnerability.Fixed in 125.0.6422.112 - Compensating control
If Chromium-based browsers cannot be mitigated (per vendor instructions), discontinue use of the product.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5274?
CVE-2024-5274 has been identified as a critical vulnerability affecting several Chromium-based browsers.
How do I fix CVE-2024-5274?
To fix CVE-2024-5274, ensure you are using the latest version of Google Chrome or Microsoft Edge (Chromium-based) as per the recommended updates.
Which products are affected by CVE-2024-5274?
CVE-2024-5274 affects Google Chrome versions up to 125.0.6422.112 and Microsoft Edge based on Chromium.
Is CVE-2024-5274 actively exploited?
Yes, Google has confirmed that CVE-2024-5274 is actively being exploited in the wild.
What are the recommended actions for CVE-2024-5274?
Users should update their browsers immediately to the latest versions to mitigate the risks associated with CVE-2024-5274.