CVE-2024-8904
published 2024-09-17CVE-2024-8904: Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.47%
37.7th percentile
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 129.0.6668.58-1~deb12u1 | 129.0.6668.58-1~deb12u1 |
| chromium | chromium | >= 0 < 129.0.6668.58-1 | 129.0.6668.58-1 |
| chromium | chromium | >= 0 < 129.0.6668.58-1 | 129.0.6668.58-1 |
| debian | chromium | < chromium 129.0.6668.58-1~deb12u1 (bookworm) | chromium 129.0.6668.58-1~deb12u1 (bookworm) |
| chrome | < 129.0.6668.58 | 129.0.6668.58 | |
| chrome | >= 129.0.6668.58 < 129.0.6668.58 | 129.0.6668.58 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0011 Chromium: Monthly Vulnerability Updates
vendor_paloalto·2024-10-09·CVSS 8.8
[HIGH] PAN-SA-2024-0011 Chromium: Monthly Vulnerability Updates
PAN-SA-2024-0011 Chromium: Monthly Vulnerability Updates
Palo Alto Networks incorporated the following Chromium security fixes into its products: - https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html - https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_24.html - https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop.html - https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_8.html CVE CVSS Summary CVE-2024-8904 Type Confusion in V8. CVE-2024-8905 Inappropriate implementation in V8. CVE-2024-8906 4.3 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N ) Incorrect security UI in Downloads. CVE-2024-8907 6.1 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N ) Insufficient data valida
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-8904
vendor_chrome·2024-10-01·CVSS 8.8
CVE-2024-8904 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-8904
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2024-8904: Type Confusion in V8. Reported by Popax21 on 2024-09-08 [$8000][ 359949835 ] Medium CVE-2024-8905: Inappropriate implementation in V8
Reported by Ganjiang Zhou(@refrain_areu) of ChaMd5-H1 team on 2024-08-15 [$1000][ 337222641 ] Low CVE-2024-8908: Inappropriate implementation in Autofill
Severity: high
Microsoft
Chromium: CVE-2024-8906 Incorrect security UI in Downloads
vendor_msrc·2024-09-10·CVSS 8.8
CVE-2024-8906 [HIGH] Chromium: CVE-2024-8906 Incorrect security UI in Downloads
Chromium: CVE-2024-8906 Incorrect security UI in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2024-09-10·CVSS 6.5
CVE-2024-43496 [MEDIUM] CWE-787 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution?
Successful exploitation of this vulnerability requires the victim user to click a malicious link in order for the attacker to initiate remote code execution on the renderer process.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
CVE-2024-8904,
129.
Microsoft
Microsoft Edge (Chromium-based) Spoofing Vulnerability
vendor_msrc·2024-09-10·CVSS 4.3
CVE-2024-38221 [MEDIUM] CWE-79 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What does that mean for this vulnerability?
Successful exploitation requires the victim to perform multiple steps to trigger the vulnerability.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site.
FAQ: What is the version informati
Microsoft
Chromium: CVE-2024-8907 Insufficient data validation in Omnibox
vendor_msrc·2024-09-10·CVSS 8.8
CVE-2024-8907 [HIGH] Chromium: CVE-2024-8907 Insufficient data validation in Omnibox
Chromium: CVE-2024-8907 Insufficient data validation in Omnibox
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft E
Microsoft
Chromium: CVE-2024-8908 Inappropriate implementation in Autofill
vendor_msrc·2024-09-10·CVSS 8.8
CVE-2024-8908 [HIGH] Chromium: CVE-2024-8908 Inappropriate implementation in Autofill
Chromium: CVE-2024-8908 Inappropriate implementation in Autofill
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2024-09-10·CVSS 6.5
CVE-2024-43489 [MEDIUM] CWE-843 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution?
Successful exploitation of this vulnerability requires the victim user to click a malicious link in order for the attacker to initiate remote code execution on the renderer process.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
CVE-2024-8904,
129.
Microsoft
Chromium: CVE-2024-8909 Inappropriate implementation in UI
vendor_msrc·2024-09-10·CVSS 8.8
CVE-2024-8909 [HIGH] Chromium: CVE-2024-8909 Inappropriate implementation in UI
Chromium: CVE-2024-8909 Inappropriate implementation in UI
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
Microsoft
Chromium: CVE-2024-8905 Inappropriate implementation in V8
vendor_msrc·2024-09-10·CVSS 8.8
CVE-2024-8905 [HIGH] Chromium: CVE-2024-8905 Inappropriate implementation in V8
Chromium: CVE-2024-8905 Inappropriate implementation in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
Microsoft
Chromium: CVE-2024-8904 Type Confusion in V8
vendor_msrc·2024-09-10·CVSS 8.8
CVE-2024-8904 [HIGH] Chromium: CVE-2024-8904 Type Confusion in V8
Chromium: CVE-2024-8904 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
FAQ: What is
Debian
CVE-2024-8904: chromium - Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote at...
vendor_debian·2024·CVSS 8.8
CVE-2024-8904 [HIGH] CVE-2024-8904: chromium - Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 129.0.6668.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 129.0.6668.58-1)
sid: resolved (fixed in 129.0.6668.58-1)
trixie: resolved (fixed in 129.0.6668.58-1)
OSV
CVE-2024-8904: Type Confusion in V8 in Google Chrome prior to 129
osv·2024-09-17·CVSS 8.8
CVE-2024-8904 [HIGH] CVE-2024-8904: Type Confusion in V8 in Google Chrome prior to 129
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
GHSA
GHSA-cwr3-4fc3-j8h8: Type Confusion in V8 in Google Chrome prior to 129
ghsa_unreviewed·2024-09-17
CVE-2024-8904 [HIGH] CWE-843 GHSA-cwr3-4fc3-j8h8: Type Confusion in V8 in Google Chrome prior to 129
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-17
Published