Vulnerability record · CVE-2024-0519 · published 16 January 2024
CVE-2024-0519: Google Chrome V8 out-of-bounds memory access
Google · Chrome
Chrome's V8 JavaScript engine contains an out-of-bounds memory access flaw fixed in versions prior to 120.0.6099.224. A crafted HTML page can trigger heap corruption, and the issue is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt attention.
Description
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is remotely reachable via a crafted page, has high CVSS impact, and is listed in CISA KEV as exploited, though it requires user interaction.
What it is
Chrome's V8 JavaScript engine contains an out-of-bounds memory access flaw fixed in versions prior to 120.0.6099.224. A crafted HTML page can trigger heap corruption, and the issue is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt attention.
Impact
An attacker who gets a victim to load a malicious page can potentially corrupt the heap and execute code in the browser's context, with high confidentiality, integrity and availability impact per the CVSS vector.
Attack surface
Reached over the network by rendering a crafted HTML page; no privileges are required but user interaction (opening the page) is needed per the CVSS vector.
Exploitation
CVE-2024-0519 is in CISA KEV with a 2024-02-07 remediation due date, indicating known exploitation; EPSS 30-day probability is about 3.8 percent (89th percentile). No ransomware campaign use is recorded.
What to do
- Update Chrome to 120.0.6099.224 or later, and apply the corresponding Fedora and Couchbase updates where those products bundle Chromium/V8.
- Track the CISA KEV due date of 2024-02-07 and confirm all exposed endpoints are patched before it.
- Enforce browser auto-update and block or restrict use of unpatched Chromium-based browsers.
- Reduce exposure by limiting browsing of untrusted sites and applying network controls where feasible.
Detection
- Monitor for Chrome/Chromium crashes or renderer process terminations that could indicate heap corruption attempts.
- Hunt proxy and DNS logs for access to known malicious or newly registered domains serving exploit pages.
- Check endpoint inventories for Chrome versions below 120.0.6099.224 and flag them for remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-0519 to the Known Exploited Vulnerabilities catalog on 17 January 2024 as "Google Chromium V8 Out-of-Bounds Memory Access Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 February 2024.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-0519 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-0519), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.