CVE-2024-7965
published 2024-08-21CVE-2024-7965: Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…
PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-09-18
Exploited in the wild
EPSS
17.23%
96.8th percentile
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 128.0.6613.84-1~deb12u1 | 128.0.6613.84-1~deb12u1 |
| chromium | chromium | >= 0 < 128.0.6613.84-1 | 128.0.6613.84-1 |
| chromium | chromium | >= 0 < 128.0.6613.84-1 | 128.0.6613.84-1 |
| debian | chromium | < chromium 128.0.6613.84-1~deb12u1 (bookworm) | chromium 128.0.6613.84-1~deb12u1 (bookworm) |
| chrome | < 128.0.6613.84 | 128.0.6613.84 | |
| chrome | >= 128.0.6613.84 < 128.0.6613.84 | 128.0.6613.84 | |
| chrome_chrome | — | — | |
| microsoft | edge_chromium | < 128.0.2739.42 | 128.0.2739.42 |
| msrc | microsoft_edge | — | — |
| paloalto | prisma_browser | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-7965 is confirmed actively exploited in the wild — flag any Chrome/Chromium-based browser version prior to 128.0.6613.84 as vulnerable and unpatched ↗
- →The vulnerability is triggered via a crafted HTML page delivered remotely — monitor for suspicious or anomalous HTML page loads in Chromium-based browsers, particularly those invoking V8 JIT/WebAssembly paths ↗
- →Exploitation can result in arbitrary code execution inside the browser sandbox — look for unusual child processes spawned from Chrome/Edge renderer processes as a post-exploitation indicator ↗
- →Microsoft Edge (Chromium-based) versions prior to 128.0.2739.42 (based on Chromium 128.0.6613.84/.85) are also affected — include Edge in asset inventory checks ↗
- →The vulnerability affects multiple Chromium-based browsers (Chrome, Edge, Opera) — broaden detection scope beyond Chrome alone when hunting for exploitation attempts ↗
- ·The fix was introduced in Chrome stable channel 128.0.6613.84 — any Chromium build below this version string should be treated as unpatched for CVE-2024-7965 ↗
- ·CISA mandated remediation by 2024-09-18 under the Known Exploited Vulnerabilities catalog — organizations still running pre-128.0.6613.84 Chromium after this date are in violation of BOD 22-01 requirements ↗
- ·Red Hat does not ship Chromium in supported offerings; Fedora/EPEL users should consider an alternative browser until updated packages are released ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0009 Prisma Browser: Monthly Vulnerability Updates
vendor_paloalto·2024-09-11·CVSS 8.8
[HIGH] PAN-SA-2024-0009 Prisma Browser: Monthly Vulnerability Updates
PAN-SA-2024-0009 Prisma Browser: Monthly Vulnerability Updates
Prisma Browser has incorporated the latest upstream Chromium security fixes listed here: - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_28.html - https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop.html - https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html CVE CVSS Summary CVE-2024-7964 8.8 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H ) Fixed in Prisma Browser 128.91.2869.7 - Chromium: Use after free in Passwords. CVE-2024-7965 8.8 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H ) Fixed in Prisma Browser 128.91.2869.7 - Chromium: Inappropri
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-7965
vendor_chrome·2024-09-09·CVSS 8.8
CVE-2024-7965 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-7965
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2024-7965: Inappropriate implementation in V8. Reported by TheDog on 2024-07-30 [$10000][ 355465305 ] High CVE-2024-7966: Out of bounds memory access in Skia
Reported by Renan Rios (@HyHy100) on 2024-07-25 [$7000][ 355731798 ] High CVE-2024-7967: Heap buffer overflow in Fonts
Severity: high
CISA
Google Chromium V8 Inappropriate Implementation Vulnerability
cisa·2024-08-28·CVSS 8.8
CVE-2024-7965 [HIGH] CWE-358 Google Chromium V8 Inappropriate Implementation Vulnerability
Vulnerability: Google Chromium V8 Inappropriate Implementation Vulnerability
Affected: Google Chromium V8
Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html; https://nvd.nist.gov/vuln/detail/CVE-2024-7965
Remediation Due Date: 2024-09-18
Red Hat
chromium-browser: Inappropriate implementation in V8 in Google Chrome allows a remote attacker to potentially exploit heap corruption
vendor_redhat·2024-08-21·CVSS 8.8
CVE-2024-7965 [HIGH] CWE-1068 chromium-browser: Inappropriate implementation in V8 in Google Chrome allows a remote attacker to potentially exploit heap corruption
chromium-browser: Inappropriate implementation in V8 in Google Chrome allows a remote attacker to potentially exploit heap corruption
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
An inappropriate implementation vulnerability was found in the Chromium web browser. This flaw allows an unauthenticated, remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Statement: Chromium is not shipped in any supported Red Hat offerings.
Mitigation: Until updated packages are released for Fedora and EPEL, consider temporarily swapping to an alternative web browser such as Firefox or severely restricting activity to site
Chrome
Stable Channel Update for Desktop: CVE-2024-7964
vendor_chrome·2024-08-21·CVSS 8.8
CVE-2024-7964 [HIGH] Stable Channel Update for Desktop: CVE-2024-7964
Stable Channel Update for Desktop
CVE-2024-7964: Use after free in Passwords. Reported by Anonymous on 2024-08-08 [$11000][ 356196918 ] High CVE-2024-7965: Inappropriate implementation in V8
Reported by TheDog on 2024-07-30 [$10000][ 355465305 ] High CVE-2024-7966: Out of bounds memory access in Skia
Severity: high
Microsoft
Chromium: CVE-2024-7965 Inappropriate implementation in V8
vendor_msrc·2024-08-13·CVSS 8.8
CVE-2024-7965 [HIGH] Chromium: CVE-2024-7965 Inappropriate implementation in V8
Chromium: CVE-2024-7965 Inappropriate implementation in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
Debian
CVE-2024-7965: chromium - Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allow...
vendor_debian·2024·CVSS 8.8
CVE-2024-7965 [HIGH] CVE-2024-7965: chromium - Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allow...
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1)
trixie: resolved (fixed in 128.0.6613.84-1)
GHSA
GHSA-x38q-hvmx-rwhg: Inappropriate implementation in V8 in Google Chrome prior to 128
ghsa_unreviewed·2024-08-21
CVE-2024-7965 [HIGH] CWE-358 GHSA-x38q-hvmx-rwhg: Inappropriate implementation in V8 in Google Chrome prior to 128
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
OSV
CVE-2024-7965: Inappropriate implementation in V8 in Google Chrome prior to 128
osv·2024-08-21·CVSS 8.8
CVE-2024-7965 [HIGH] CVE-2024-7965: Inappropriate implementation in V8 in Google Chrome prior to 128
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
VulnCheck
Google Chromium V8 Inappropriate Implementation Vulnerability
vulncheck·2024·CVSS 8.8
CVE-2024-7965 [HIGH] CWE-358 Google Chromium V8 Inappropriate Implementation Vulnerability
Google Chromium V8 Inappropriate Implementation Vulnerability
Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Affected: Google Chromium V8
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html; https://www.cisa.gov/sites/default/files/feeds/known_explo
Suricata
ET WEB_SPECIFIC_APPS TECHNOTE shop_this_skin_path Parameter Remote File Inclusion
suricata·2010-07-30·CVSS 6.8
CVE-2009-0441 [MEDIUM] ET WEB_SPECIFIC_APPS TECHNOTE shop_this_skin_path Parameter Remote File Inclusion
ET WEB_SPECIFIC_APPS TECHNOTE shop_this_skin_path Parameter Remote File Inclusion
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS TECHNOTE shop_this_skin_path Parameter Remote File Inclusion"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/body_default.php?"; nocase; content:"GOODS[no]="; nocase; content:"GOODS[gs_input]="; nocase; content:"shop_this_skin_path="; nocase; pcre:"/shop_this_skin_path=\s*(https?|ftps?|php)\:\//i"; reference:url,secunia.com/advisories/33732/; reference:cve,CVE-2009-0441; reference:url,milw0rm.com/exploits/7965; classtype:web-application-attack; sid:2009229; rev:8; metadata:created_at 2010_07_30, signature_severity Major, updated_at 2024_03_06, mitre_tactic_id TA0001, mitre_tactic_name Initial_Acce
No public exploits indexed.
Checkpoint
2nd September – Threat Intelligence Report
blogs_checkpoint·2024-09-02
CVE-2024-6386 2nd September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2nd September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 26th August, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
California-based Patelco Credit Union has confirmed a data breach following a ransomware attack resulted in the exposure of sensitive personal information belongs to 726K clients and employees. The compromised data includes names, Social Security numbers, driver’s license numbers, dates of birth, and email addresses. The
Bleepingcomputer
Google tags a tenth Chrome zero-day as exploited this year
blogs_bleepingcomputer·2024-08-26·CVSS 8.8
CVE-2024-7971 [HIGH] Google tags a tenth Chrome zero-day as exploited this year
## Google tags a tenth Chrome zero-day as exploited this year
## Sergiu Gatlan
This was announced in an update to a blog post where the company revealed last week that it had fixed another high-severity zero-day vulnerability (CVE-2024-7971) caused by a V8 type confusion weakness.
"Updated on 26 August 2024 to reflect the in the wild exploitation of CVE-2024-7965 which was reported after this release," the company said in today's update . "Google is aware that exploits for CVE-2024-7971 and CVE-2024-7965 exist in the wild."
Google has fixed both zero-days in Chrome version 128.0.6613.84/.85 for Windows/macOS systems and version 128.0.6613.84 Linux users, which have been rolling out to all users in the Stable Desktop channel since Wednesday.
Even though Chrome will automatically update
2024-08-21
Published
2024-08-28
Added to CISA KEV
Exploited in the wild