CVE-2024-7971
published 2024-08-21CVE-2024-7971: Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security…
PriorityP188critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-09-16
Exploited in the wild
EPSS
19.27%
97.0th percentile
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 128.0.6613.84-1~deb12u1 | 128.0.6613.84-1~deb12u1 |
| chromium | chromium | >= 0 < 128.0.6613.84-1 | 128.0.6613.84-1 |
| chromium | chromium | >= 0 < 128.0.6613.84-1 | 128.0.6613.84-1 |
| debian | chromium | < chromium 128.0.6613.84-1~deb12u1 (bookworm) | chromium 128.0.6613.84-1~deb12u1 (bookworm) |
| chrome | < 128.0.6613.84 | 128.0.6613.84 | |
| chrome | >= 128.0.6613.84 < 128.0.6613.84 | 128.0.6613.84 | |
| chrome_chrome | — | — | |
| microsoft | edge | < 128.0.2739.42 | 128.0.2739.42 |
| msrc | microsoft_edge | — | — |
| paloalto | prisma_browser | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for browser processes making outbound connections to attacker-controlled domains voyagorclub[.]space and weinsteinfrog[.]com, which were used to deliver the CVE-2024-7971 V8 type confusion exploit via drive-by redirect. ↗
- →Alert on Chrome/Edge (Chromium-based) versions prior to 128.0.6613.84 (Chrome) or Edge 128.0.2739.42 being used in the environment, as these are vulnerable to CVE-2024-7971 exploitation in the wild. ↗
- ·The exploit chain requires both CVE-2024-7971 (Chrome V8 RCE for renderer sandbox entry) AND CVE-2024-38106 (Windows Kernel sandbox escape for SYSTEM privilege escalation); patching only Chrome without patching the Windows Kernel leaves the full chain partially viable. ↗
- ·Chromium is not shipped in any supported Red Hat offerings, so Red Hat-based systems are not directly affected by this CVE through vendor packages. ↗
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv9.6CRITICAL
vulncheck9.6CRITICAL
cisa9.6CRITICAL
vendor_debian9.6CRITICAL
vendor_msrc9.6CRITICAL
vendor_redhat9.6CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2024-7971
vendor_chrome·2024-10-29·CVSS 9.6
CVE-2024-7971 [CRITICAL] Long Term Support Channel Update for ChromeOS: CVE-2024-7971
Long Term Support Channel Update for ChromeOS
CVE-2024-7971
Palo Alto
PAN-SA-2024-0009 Prisma Browser: Monthly Vulnerability Updates
vendor_paloalto·2024-09-11·CVSS 8.8
[HIGH] PAN-SA-2024-0009 Prisma Browser: Monthly Vulnerability Updates
PAN-SA-2024-0009 Prisma Browser: Monthly Vulnerability Updates
Prisma Browser has incorporated the latest upstream Chromium security fixes listed here: - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_28.html - https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop.html - https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html CVE CVSS Summary CVE-2024-7964 8.8 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H ) Fixed in Prisma Browser 128.91.2869.7 - Chromium: Use after free in Passwords. CVE-2024-7965 8.8 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H ) Fixed in Prisma Browser 128.91.2869.7 - Chromium: Inappropri
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-7968
vendor_chrome·2024-09-09·CVSS 8.8
CVE-2024-7968 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-7968
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2024-7968: Use after free in Autofill. Reported by Han Zheng (HexHive) on 2024-06-25 [TBD][ 360700873 ] High CVE-2024-7971: Type confusion in V8
Reported by Microsoft Threat Intelligence Center (MSTIC), Microsoft Security Response Center (MSRC) on 2024-08-19 [$11000][ 345960102 ] Medium CVE-2024-7972: Inappropriate implementation in V8
Severity: high
CISA
Google Chromium V8 Type Confusion Vulnerability
cisa·2024-08-26·CVSS 9.6
CVE-2024-7971 [CRITICAL] CWE-843 Google Chromium V8 Type Confusion Vulnerability
Vulnerability: Google Chromium V8 Type Confusion Vulnerability
Affected: Google Chromium V8
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html; https://nvd.nist.gov/vuln/detail/CVE-2024-7971
Remediation Due Date: 2024-09-16
Red Hat
chromium-browser: Type confusion in V8 in Google Chrome allows a remote attacker to exploit heap corruption via a crafted HTML page
vendor_redhat·2024-08-21·CVSS 9.6
CVE-2024-7971 [CRITICAL] CWE-843 chromium-browser: Type confusion in V8 in Google Chrome allows a remote attacker to exploit heap corruption via a crafted HTML page
chromium-browser: Type confusion in V8 in Google Chrome allows a remote attacker to exploit heap corruption via a crafted HTML page
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
A type confusion vulnerability was found in the Chromium web browser. This flaw allows an unauthenticated, remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Statement: Chromium is not shipped in any supported Red Hat offerings.
Mitigation: Until updated packages are released for Fedora and EPEL, consider temporarily swapping to an alternative web browser such as Firefox or severely restricting activity to sites you know well and trust.
Microsoft
Chromium: CVE-2024-7971 Type confusion in V8
vendor_msrc·2024-08-13·CVSS 9.6
CVE-2024-7971 [CRITICAL] Chromium: CVE-2024-7971 Type confusion in V8
Chromium: CVE-2024-7971 Type confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Google is aware that an exploit for CVE-2024-7971 exists in the wild.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Cl
Debian
CVE-2024-7971: chromium - Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote at...
vendor_debian·2024·CVSS 9.6
CVE-2024-7971 [CRITICAL] CVE-2024-7971: chromium - Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1)
trixie: resolved (fixed in 128.0.6613.84-1)
GHSA
GHSA-pq5w-h3jm-m95c: Type confusion in V8 in Google Chrome prior to 128
ghsa_unreviewed·2024-08-21
CVE-2024-7971 [HIGH] CWE-843 GHSA-pq5w-h3jm-m95c: Type confusion in V8 in Google Chrome prior to 128
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
OSV
CVE-2024-7971: Type confusion in V8 in Google Chrome prior to 128
osv·2024-08-21·CVSS 9.6
CVE-2024-7971 [CRITICAL] CVE-2024-7971: Type confusion in V8 in Google Chrome prior to 128
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
VulnCheck
Google Chromium V8 Type Confusion Vulnerability
vulncheck·2024·CVSS 9.6
CVE-2024-7971 [CRITICAL] CWE-843 Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Affected: Google Chromium V8
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.mi
No detection rules found.
No public exploits indexed.
Talos
The best and worst ways to get users to improve their account security
blogs_talos·2024-09-05
The best and worst ways to get users to improve their account security
## The best and worst ways to get users to improve their account security
As most quality thoughts go, my most recent musing on security came about because of fantasy football.
I had to log into my Yahoo Sports account, which I admittedly only ever have to log in to, at most, three times a year for the one fantasy football draft I have on that platform each year and then the handful of other times my phone logs me out during the five months that I’m adjusting my lineups on a weekly basis.
Admittedly, I’d never thought much about the security of my Yahoo Sports account because I don’t have any sensitive information tied to it, and if someone did want to break in, they could probably do a better job of managing my team in that league than I have the past few years. It’s the old “out of si
Talos
The best and worst ways to get users to improve their account security
blogs_talos·2024-09-05
The best and worst ways to get users to improve their account security
As most quality thoughts go, my most recent musing on security came about because of fantasy football.
I had to log into my Yahoo Sports account, which I admittedly only ever have to log in to, at most, three times a year for the one fantasy football draft I have on that platform each year and then the handful of other times my phone logs me out during the five months that I’m adjusting my lineups on a weekly basis.
Admittedly, I’d never thought much about the security of my Yahoo Sports account because I don’t have any sensitive information tied to it, and if someone did want to break in, they could probably do a better job of managing my team in that league than I have the past few years. It’s the old “out of sight, out of mind” compared to something like my work email account where I’
Bleepingcomputer
North Korean hackers exploit Chrome zero-day to deploy rootkit
blogs_bleepingcomputer·2024-08-30·CVSS 7.0
[HIGH] North Korean hackers exploit Chrome zero-day to deploy rootkit
## North Korean hackers exploit Chrome zero-day to deploy rootkit
## Sergiu Gatlan
Citrine Sleet targets financial institutions, focusing on cryptocurrency organizations and associated individuals, and has been previously linked to Bureau 121 of North Korea's Reconnaissance General Bureau.
The North Korean hackers are also known for using malicious websites camouflaged as legitimate cryptocurrency trading platforms to infect potential victims with fake job applications or weaponized cryptocurrency wallets or trading apps.
UNC4736 trojanized the Electron-based desktop client of video conferencing software maker 3CX in March 2023, following a previous supply-chain attack in which they breached the site of Trading Technologies , a stock trading automation company, to push trojanized X_TRA
Microsoft
North Korean threat actor Citrine Sleet exploiting Chromium zero-day
blogs_microsoft·2024-08-30·CVSS 9.6
CVE-2024-7971 [CRITICAL] North Korean threat actor Citrine Sleet exploiting Chromium zero-day
Research
August 30, 2024
## Indicators of compromise
During the attacks, Microsoft observed the following IOCs:
voyagorclub[.]space
weinsteinfrog[.]com
## References
https://nvd.nist.gov/vuln/detail/CVE-2024-7971
https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html
https://nvd.nist.gov/vuln/detail/CVE-2024-4947
https://nvd.nist.gov/vuln/detail/CVE-2024-5274
https://decoded.avast.io/janvojtesek/lazarus-and-the-fudmodule-rootkit-beyond-byovd-with-an-admin-to-kernel-zero-day/
https://www.virusbulletin.com/uploads/pdf/conference/vb2022/papers/VB2022-Lazarus-and-BYOVD-evil-to-the-Windows-core.pdf
https://asec.ahnlab.com/wp-content/uploads/2022/09/Analysis-Report-on-Lazarus-Groups-Rootkit-Attack-Using-BYOVD_Sep-22-2022.pdf
https://decoded.avas
Bleepingcomputer
Google tags a tenth Chrome zero-day as exploited this year
blogs_bleepingcomputer·2024-08-26·CVSS 8.8
CVE-2024-7971 [HIGH] Google tags a tenth Chrome zero-day as exploited this year
## Google tags a tenth Chrome zero-day as exploited this year
## Sergiu Gatlan
This was announced in an update to a blog post where the company revealed last week that it had fixed another high-severity zero-day vulnerability (CVE-2024-7971) caused by a V8 type confusion weakness.
"Updated on 26 August 2024 to reflect the in the wild exploitation of CVE-2024-7965 which was reported after this release," the company said in today's update . "Google is aware that exploits for CVE-2024-7971 and CVE-2024-7965 exist in the wild."
Google has fixed both zero-days in Chrome version 128.0.6613.84/.85 for Windows/macOS systems and version 128.0.6613.84 Linux users, which have been rolling out to all users in the Stable Desktop channel since Wednesday.
Even though Chrome will automatically update
Bleepingcomputer
Google fixes ninth Chrome zero-day tagged as exploited this year
blogs_bleepingcomputer·2024-08-21·CVSS 8.8
CVE-2024-7971 [HIGH] Google fixes ninth Chrome zero-day tagged as exploited this year
## Google fixes ninth Chrome zero-day tagged as exploited this year
## Sergiu Gatlan
Today, Google released a new Chrome emergency security update to patch a zero-day vulnerability tagged as exploited in attacks.
"Google is aware that an exploit for CVE-2024-7971 exists in the wild," the company said in an advisory published on Wednesday.
This high-severity zero-day vulnerability is caused by a type confusion weakness in Chrome's V8 JavaScript engine. Security researchers with the Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) reported it on Monday.
Although such security flaws can commonly enable attackers to trigger browser crashes after data allocated into memory is interpreted as a different type, they can also exploit them for arbitra
https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.htmlhttps://issues.chromium.org/issues/360700873https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7971
2024-08-21
Published
2024-08-26
Added to CISA KEV
Exploited in the wild