Out of bounds memory access vulnerability in Google Chrome
Key Information
- Vendor
- Status
- Chrome
- Vendor
- CVE Published:
- 16 January 2024
Badges
Summary
A high-severity zero-day bug, CVE-2024-0519, has been identified in Google Chrome and is actively exploited by attackers. This vulnerability, found in the V8 JavaScript engine, allows for out-of-bounds memory access, potentially leading to heap corruption and enabling remote attackers to exploit it via a crafted HTML page. Potential impacts include unauthorized memory access, system crashes, data modification, and code injection. The sheer volume of zero-day bugs disclosed in Chrome and browsers based on Chromium technology, along with the widespread use and targeting of browser technologies by attackers, highlights the urgency for organizations and individuals to update to the latest patched versions to mitigate such risks.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-0519 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
Chrome < 120.0.6099.224
News Articles
CVE-2023-51363 Archives
VulnerabilityDecember 27, 2023The Urgent Need to Patch Buffalo’s VR-S1000 VPN RouterIn the digital era, small and medium-sized businesses have become increasingly reliant on the Internet for their daily...
10 months ago
Google Chrome Multiple Vulnerabilities
Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.
10 months ago
Google Chrome Zero-Day Bug Under Attack, Allows Code Injection
The first Chrome zero-day bug of 2024 adds to a growing list of actively exploited vulnerabilities found in Chromium and other browser technologies.
10 months ago
CVSS V3.1
Timeline
Vulnerability started trending.
- 👾
Exploit exists.
First article discovered by SecurityWeek
Vulnerability published.
Vulnerability Reserved.