Vulnerability record · CVE-2024-4947 · published 15 May 2024
CVE-2024-4947: Google Chrome V8 type confusion allows sandboxed remote code execution
Google · Chrome
Google Chrome before 125.0.6422.60 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and let a remote attacker execute arbitrary code inside the browser sandbox. It is a high-severity Chromium issue that was added to CISA KEV, so it warrants prompt patching.
Description
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.6, active inclusion in CISA KEV with a near-term due date, and an exploit-tagged reference make this a critical patching priority.
What it is
Google Chrome before 125.0.6422.60 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and let a remote attacker execute arbitrary code inside the browser sandbox. It is a high-severity Chromium issue that was added to CISA KEV, so it warrants prompt patching.
Impact
An attacker who gets a victim to load a malicious page can run arbitrary code within the Chrome sandbox, potentially leading to further compromise of the host. The CVSS vector rates confidentiality, integrity and availability impact as high with scope change.
Attack surface
Reached over the network by a crafted HTML page rendered in Chrome; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N). No authentication is needed, but the victim must open or be directed to the malicious page.
Exploitation
CVE-2024-4947 is listed in CISA KEV with a due date of 2024-06-10, and a Chromium issue reference is tagged Exploit. EPSS gives a 30-day probability of about 15.2 percent (96.6th percentile), indicating observed exploitation activity.
What to do
- Upgrade Google Chrome to 125.0.6422.60 or later, and apply the corresponding Fedora package updates.
- Track the CISA KEV due date of 2024-06-10 and confirm all managed Chrome endpoints are patched before it.
- If immediate patching is not possible, follow vendor mitigations or discontinue use of the affected product as CISA advises.
- Enforce browser auto-update and verify version compliance across the fleet.
- Limit exposure by restricting browsing to trusted sites and blocking known malicious domains where feasible.
Detection
- Monitor for Chrome processes spawning unexpected child processes or writing unusual files, which can indicate sandbox escape or code execution.
- Hunt for crashes or renderer anomalies in Chrome around V8, and correlate with visits to untrusted or newly registered domains.
- Check endpoint and proxy logs for Chrome versions below 125.0.6422.60 and prioritize those hosts for patching.
- Review web proxy and DNS logs for known exploit delivery infrastructure tied to Chrome V8 campaigns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-4947 to the Known Exploited Vulnerabilities catalog on 20 May 2024 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 10 June 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-4947 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-4947), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.