Vulnerability record · CVE-2024-4761 · published 14 May 2024
CVE-2024-4761: Google Chrome V8 Out-of-Bounds Write via Crafted HTML Page
Google · Chrome
CVE-2024-4761 is an out-of-bounds write in the V8 JavaScript engine in Google Chrome prior to 124.0.6367.207. A remote attacker can trigger the memory corruption by getting a victim to load a crafted HTML page, which can lead to code execution or a crash in the browser process. The flaw is rated High by Chromium and carries a CVSS 3.1 base score of 8.8.
Description
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is in CISA's KEV catalog, indicating active exploitation, and allows remote code execution with only user interaction on a widely deployed browser.
What it is
CVE-2024-4761 is an out-of-bounds write in the V8 JavaScript engine in Google Chrome prior to 124.0.6367.207. A remote attacker can trigger the memory corruption by getting a victim to load a crafted HTML page, which can lead to code execution or a crash in the browser process. The flaw is rated High by Chromium and carries a CVSS 3.1 base score of 8.8.
Impact
An attacker who successfully exploits the out-of-bounds write can corrupt memory in the renderer and potentially achieve arbitrary code execution in the context of the browser. This can lead to full compromise of the user's session, data theft, or further lateral movement from the workstation.
Attack surface
The vulnerability is reached over the network through a crafted HTML page rendered by Chrome, requiring no privileges but requiring user interaction to visit or open the page. The CVSS vector AV:N/AC:L/PR:N/UI:R confirms remote, low-complexity exploitation with user interaction.
Exploitation
CVE-2024-4761 was added to CISA's Known Exploited Vulnerabilities catalog on 2024-05-16 with a remediation due date of 2024-06-06, indicating exploitation in the wild. EPSS gives a 30-day exploitation probability of 0.11007, placing it in the 95.7th percentile.
What to do
- Update Google Chrome to version 124.0.6367.207 or later immediately; this is the primary remediation.
- Apply the corresponding Fedora package updates referenced in the Fedora package-announce mailing lists.
- If immediate patching is not possible, follow CISA KEV required action: apply vendor mitigations or discontinue use of the affected product.
- Enforce automatic browser updates and verify version compliance across managed endpoints.
- Restrict or monitor browsing to untrusted sites where feasible until patching is complete.
Detection
- Monitor for Chrome renderer crashes or abnormal process terminations that may indicate exploitation attempts.
- Hunt for network requests or file downloads delivering HTML pages that trigger V8 memory corruption, using endpoint detection for suspicious browser child processes.
- Check endpoint telemetry for Chrome versions below 124.0.6367.207 to identify unpatched assets.
- Review proxy or DNS logs for known exploit delivery domains if threat intelligence is available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-4761 to the Known Exploited Vulnerabilities catalog on 16 May 2024 as "Google Chromium V8 Out-of-Bounds Memory Write Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 6 June 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-4761 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-4761), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.