← Vulnerability feed

Vulnerability record · CVE-2024-4947 · published 15 May 2024

CVE-2024-4947: Google Chrome V8 type confusion allows sandboxed remote code execution

Google · Chrome

Google Chrome before 125.0.6422.60 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and let a remote attacker execute arbitrary code inside the browser sandbox. It is a high-severity Chromium issue that was added to CISA KEV, so it warrants prompt patching.

9.6 CVSS 3.1 Critical CISA KEV since 20 May 2024 EPSS 15% · top 3.4% CWE-843 · Type confusion
9.6CVSS 3.1 base score
15%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
11References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.6, active inclusion in CISA KEV with a near-term due date, and an exploit-tagged reference make this a critical patching priority.

What it is

Google Chrome before 125.0.6422.60 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and let a remote attacker execute arbitrary code inside the browser sandbox. It is a high-severity Chromium issue that was added to CISA KEV, so it warrants prompt patching.

Impact

An attacker who gets a victim to load a malicious page can run arbitrary code within the Chrome sandbox, potentially leading to further compromise of the host. The CVSS vector rates confidentiality, integrity and availability impact as high with scope change.

Attack surface

Reached over the network by a crafted HTML page rendered in Chrome; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N). No authentication is needed, but the victim must open or be directed to the malicious page.

Exploitation

CVE-2024-4947 is listed in CISA KEV with a due date of 2024-06-10, and a Chromium issue reference is tagged Exploit. EPSS gives a 30-day probability of about 15.2 percent (96.6th percentile), indicating observed exploitation activity.

What to do

  • Upgrade Google Chrome to 125.0.6422.60 or later, and apply the corresponding Fedora package updates.
  • Track the CISA KEV due date of 2024-06-10 and confirm all managed Chrome endpoints are patched before it.
  • If immediate patching is not possible, follow vendor mitigations or discontinue use of the affected product as CISA advises.
  • Enforce browser auto-update and verify version compliance across the fleet.
  • Limit exposure by restricting browsing to trusted sites and blocking known malicious domains where feasible.

Detection

  • Monitor for Chrome processes spawning unexpected child processes or writing unusual files, which can indicate sandbox escape or code execution.
  • Hunt for crashes or renderer anomalies in Chrome around V8, and correlate with visits to untrusted or newly registered domains.
  • Check endpoint and proxy logs for Chrome versions below 125.0.6422.60 and prioritize those hosts for patching.
  • Review web proxy and DNS logs for known exploit delivery infrastructure tied to Chrome V8 campaigns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-4947 to the Known Exploited Vulnerabilities catalog on 20 May 2024 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 10 June 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-4947 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed

Source: NIST National Vulnerability Database (record CVE-2024-4947), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.