CVE-2024-3174Cross-site Scripting in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.7%
top 27.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateSep 27

Description

Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5google/chrome119.0.6045.105119.0.6045.105
NVDgoogle/chrome< 119.0.6045.105
debiandebian/chromium< chromium 119.0.6045.105-1~deb12u1 (bookworm)
Debianchromium/chromium< 119.0.6045.105-1~deb11u1+3

🔴Vulnerability Details

2
GHSA
GHSA-qw4m-qq5c-43c6: Inappropriate implementation in V8 in Google Chrome prior to 1192024-07-17
OSV
CVE-2024-3174: Inappropriate implementation in V8 in Google Chrome prior to 1192024-07-16

📋Vendor Advisories

3
Red Hat
kernel: perf/x86/intel: Limit the period on Haswell2024-09-27
Debian
CVE-2024-3174: chromium - Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allo...2024
Chrome
Stable Channel Update for Desktop: CVE-2024-31742023-10-31
CVE-2024-3174 — Cross-site Scripting in Google Chrome | cvebase