CVE-2024-3159
published 2024-04-06CVE-2024-3159: Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page…
PriorityP352high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.60%
73.2th percentile
Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 123.0.6312.105-1~deb12u1 | 123.0.6312.105-1~deb12u1 |
| chromium | chromium | >= 0 < 123.0.6312.105-1 | 123.0.6312.105-1 |
| chromium | chromium | >= 0 < 123.0.6312.105-1 | 123.0.6312.105-1 |
| debian | chromium | < chromium 123.0.6312.105-1~deb12u1 (bookworm) | chromium 123.0.6312.105-1~deb12u1 (bookworm) |
| chrome | < 123.0.6312.105 | 123.0.6312.105 | |
| chrome | >= 123.0.6312.105 < 123.0.6312.105 | 123.0.6312.105 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
| msrc | microsoft_edge_extended_stable | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Chromium: CVE-2024-3159 Out of bounds memory access in V8
vendor_msrc·2024-04-09·CVSS 8.8
CVE-2024-3159 [HIGH] Chromium: CVE-2024-3159 Out of bounds memory access in V8
Chromium: CVE-2024-3159 Out of bounds memory access in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
Chrome
Stable Channel Update for Desktop: CVE-2024-3156
vendor_chrome·2024-04-02·CVSS 8.8
CVE-2024-3156 [HIGH] Stable Channel Update for Desktop: CVE-2024-3156
Stable Channel Update for Desktop
CVE-2024-3156: Inappropriate implementation in V8. Reported by Zhenghang Xiao (@Kipreyyy) on 2024-03-12 [$3000][ 329965696 ] High CVE-2024-3158: Use after free in Bookmarks
Reported by undoingfish on 2024-03-17 [N/A][ 330760873 ] High CVE-2024-3159: Out of bounds memory access in V8
Severity: high
Debian
CVE-2024-3159: chromium - Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allow...
vendor_debian·2024·CVSS 8.8
CVE-2024-3159 [HIGH] CVE-2024-3159: chromium - Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allow...
Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 123.0.6312.105-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.105-1)
sid: resolved (fixed in 123.0.6312.105-1)
trixie: resolved (fixed in 123.0.6312.105-1)
OSV
CVE-2024-3159: Out of bounds memory access in V8 in Google Chrome prior to 123
osv·2024-04-06·CVSS 8.8
CVE-2024-3159 [HIGH] CVE-2024-3159: Out of bounds memory access in V8 in Google Chrome prior to 123
Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
GHSA
GHSA-mh2p-2x66-3hr4: Out of bounds memory access in V8 in Google Chrome prior to 123
ghsa_unreviewed·2024-04-06
CVE-2024-3159 [HIGH] CWE-119 GHSA-mh2p-2x66-3hr4: Out of bounds memory access in V8 in Google Chrome prior to 123
Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Google tags a tenth Chrome zero-day as exploited this year
blogs_bleepingcomputer·2024-08-26·CVSS 8.8
CVE-2024-7971 [HIGH] Google tags a tenth Chrome zero-day as exploited this year
## Google tags a tenth Chrome zero-day as exploited this year
## Sergiu Gatlan
This was announced in an update to a blog post where the company revealed last week that it had fixed another high-severity zero-day vulnerability (CVE-2024-7971) caused by a V8 type confusion weakness.
"Updated on 26 August 2024 to reflect the in the wild exploitation of CVE-2024-7965 which was reported after this release," the company said in today's update . "Google is aware that exploits for CVE-2024-7971 and CVE-2024-7965 exist in the wild."
Google has fixed both zero-days in Chrome version 128.0.6613.84/.85 for Windows/macOS systems and version 128.0.6613.84 Linux users, which have been rolling out to all users in the Stable Desktop channel since Wednesday.
Even though Chrome will automatically update
Bleepingcomputer
Google fixes ninth Chrome zero-day tagged as exploited this year
blogs_bleepingcomputer·2024-08-21·CVSS 8.8
CVE-2024-7971 [HIGH] Google fixes ninth Chrome zero-day tagged as exploited this year
## Google fixes ninth Chrome zero-day tagged as exploited this year
## Sergiu Gatlan
Today, Google released a new Chrome emergency security update to patch a zero-day vulnerability tagged as exploited in attacks.
"Google is aware that an exploit for CVE-2024-7971 exists in the wild," the company said in an advisory published on Wednesday.
This high-severity zero-day vulnerability is caused by a type confusion weakness in Chrome's V8 JavaScript engine. Security researchers with the Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) reported it on Monday.
Although such security flaws can commonly enable attackers to trigger browser crashes after data allocated into memory is interpreted as a different type, they can also exploit them for arbitra
Bleepingcomputer
Google fixes eighth actively exploited Chrome zero-day this year
blogs_bleepingcomputer·2024-05-24·CVSS 8.8
[HIGH] Google fixes eighth actively exploited Chrome zero-day this year
## Google fixes eighth actively exploited Chrome zero-day this year
## Bill Toulas
A "type confusion" vulnerability occurs when a program allocates a piece of memory to hold a certain type of data but mistakenly interprets the data as a different type. This can lead to crashes, data corruption, as well as arbitrary code execution.
Google has not shared technical details about the flaw to protect users from potential exploitation attempts from other threat actors and allow them to install a browser version that addresses the problem.
"Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed," said the t
Bleepingcomputer
Google fixes third actively exploited Chrome zero-day in a week
blogs_bleepingcomputer·2024-05-15·CVSS 8.8
CVE-2024-4671 [HIGH] Google fixes third actively exploited Chrome zero-day in a week
## Google fixes third actively exploited Chrome zero-day in a week
## Sergiu Gatlan
Although such flaws generally enable threat actors to trigger browser crashes by reading or writing memory out of buffer bounds, they can also exploit them for arbitrary code execution on targeted devices.
The other two actively exploited Chrome zero-days patched this week are CVE-2024-4671 (a use-after-free flaw in the Visuals component) and CVE-2024-4761 (an out-of-bounds write bug in the V8 JavaScript engine).
Microsoft also said it's "aware of the recent exploits existing in the wild" targeting CVE-2024-4947 and that its engineers are "actively working on releasing a security fix" for the Chromium-based Edge web browser.
## Fix rolling out to Stable channel users
The company fixed the zero-day fla
Bleepingcomputer
Google Chrome emergency update fixes 6th zero-day exploited in 2024
blogs_bleepingcomputer·2024-05-14·CVSS 8.8
CVE-2024-4761 [HIGH] Google Chrome emergency update fixes 6th zero-day exploited in 2024
## Google Chrome emergency update fixes 6th zero-day exploited in 2024
## Bill Toulas
Out-of-bounds write issues occur when a program is allowed to write data outside the specified array or buffer, potentially leading to unauthorized data access, arbitrary code execution, or program crashes.
“Google is aware that an exploit for CVE-2024-4761 exists in the wild,” reads the advisory .
The company fixed the security flaw with the release of 124.0.6367.207/.208 for Mac/Windows and 124.0.6367.207 for Linux. The updates will roll out to all users over the coming days/weeks.
For users of the ‘Extended Stable’ channel, fixes will be made available in version 124.0.6367.207 for Mac and Windows.
Chrome updates automatically when a security update is available, but users can confirm they’re run
Bleepingcomputer
Google fixes fifth Chrome zero-day exploited in attacks this year
blogs_bleepingcomputer·2024-05-10·CVSS 8.8
CVE-2024-4671 [HIGH] Google fixes fifth Chrome zero-day exploited in attacks this year
## Google fixes fifth Chrome zero-day exploited in attacks this year
## Bill Toulas
“Google is aware that an exploit for CVE-2024-4671 exists in the wild,” reads the advisory , without providing additional information.
Use after-free flaws are security flaws that occur when a program continues to use a pointer after the memory it points to has been freed, following the completion of its legitimate operations on that region.
Because the freed memory could now contain different data or be used by other software or components, accessing it could result in data leakage, code execution, or crash.
Google addressed the problem with the release of 124.0.6367.201/.202 for Mac/Windows and 124.0.6367.201 for Linux, with the updates rolling out over the coming days/weeks.
For users of the ‘Exten
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
# The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs
2024/04/09
Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager, however, all of the bugs being patched are simple Cross
Bleepingcomputer
Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
blogs_bleepingcomputer·2024-04-09·CVSS 8.1
[HIGH] Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Lawrence Abrams
There were also fixes for twenty-six Secure Boot bypasses released this month, including two from Lenovo.
The number of bugs in each vulnerability category is listed below:
31 Elevation of Privilege Vulnerabilities
29 Security Feature Bypass Vulnerabilities
67 Remote Code Execution Vulnerabilities
13 Information Disclosure Vulnerabilities
7 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The total count of 150 flaws does not include 5 Microsoft Edge flaws fixed on April 4th and 2 Mariner flaws. Mariner is an open-source Linux distribution developed by Microsoft for its Microsoft Azure services.
To learn more about the non-security updates released today, you can review our ded
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
## The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs 2024/04/09 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager , however, all of the bugs being patched are simple Cros
Bugzilla
CVE-2024-35837 kernel: net: mvpp2: clear BM pool before initialization
bugzilla·2024-05-17·CVSS 5.5
CVE-2024-35837 [MEDIUM] CVE-2024-35837 kernel: net: mvpp2: clear BM pool before initialization
CVE-2024-35837 kernel: net: mvpp2: clear BM pool before initialization
In the Linux kernel, the following vulnerability has been resolved:
net: mvpp2: clear BM pool before initialization
The Linux kernel CVE team has assigned CVE-2024-35837 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051731-CVE-2024-35837-3159@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281160]
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2024-35837 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built).
https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop.htmlhttps://issues.chromium.org/issues/330760873https://lists.fedoraproject.org/archives/list/[email protected]/message/EVEJEW7UCSUSK2J2FYQRZZPI74P2D3JP/https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop.htmlhttps://issues.chromium.org/issues/330760873https://lists.fedoraproject.org/archives/list/[email protected]/message/EVEJEW7UCSUSK2J2FYQRZZPI74P2D3JP/https://lists.fedoraproject.org/archives/list/[email protected]/message/U26WECLV5QAQVTIFAUDSRO6QX3NTHYVC/
2024-04-06
Published