Vulnerability record · CVE-2024-7965 · published 21 August 2024
CVE-2024-7965: Google Chrome V8 inappropriate implementation allows heap corruption
Google · Chrome
Google Chrome before 128.0.6613.84 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. The flaw is remotely reachable through a crafted HTML page and is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Description
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityConfirmed in-the-wild exploitation (CISA KEV) and a high CVSS score of 8.8 with network reachability make this a high-priority patch despite requiring user interaction.
What it is
Google Chrome before 128.0.6613.84 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. The flaw is remotely reachable through a crafted HTML page and is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Impact
An attacker who gets a victim to load a crafted page can corrupt the heap, which can lead to code execution or a browser crash in the context of the user.
Attack surface
Reached over the network by rendering a crafted HTML page in Chrome or Chromium-based Edge; no authentication is required but user interaction (visiting the page) is needed per the CVSS vector.
Exploitation
CVE-2024-7965 was added to CISA KEV on 2024-08-28 with a 2024-09-18 due date, indicating known exploitation in the wild; EPSS gives a 30-day probability of 0.185 (97th percentile). No ransomware campaign use is documented.
What to do
- Update Google Chrome to 128.0.6613.84 or later and Microsoft Edge to its corresponding patched Chromium build.
- Apply mitigations per vendor instructions or discontinue use of the affected product if patching is not possible, per the CISA KEV required action.
- Prioritize patching internet-facing and high-value endpoints first, given confirmed exploitation.
- Verify browser version compliance across managed fleets and block or restrict use of unpatched Chromium-based browsers.
Detection
- Monitor for Chrome or Chromium-based browser crashes consistent with heap corruption, especially following visits to untrusted sites.
- Hunt for exploit delivery via crafted HTML pages, malicious ads, or compromised sites in web proxy and DNS logs.
- Track browser version inventory to identify endpoints still running Chrome below 128.0.6613.84.
- Review endpoint telemetry for suspicious child processes or code execution originating from browser processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-7965 to the Known Exploited Vulnerabilities catalog on 28 August 2024 as "Google Chromium V8 Inappropriate Implementation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 18 September 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html | Release Notes |
| https://issues.chromium.org/issues/356196918 | Permissions Required |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7965 | US Government Resource |
Track CVE-2024-7965 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-7965), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.