Vulnerability record · CVE-2024-7971 · published 21 August 2024
CVE-2024-7971: Google Chrome V8 type confusion enables heap corruption
Google · Chrome
Chrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a crafted HTML page corrupt the heap. It affects Chrome before 128.0.6613.84 and, per the vendor list, Microsoft Edge. Because it is a browser engine bug reachable from web content, it is a serious remote code execution risk.
Description
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Automated analysis
critical priorityConfirmed in-the-wild exploitation (KEV, nation-state attribution) with a critical CVSS of 9.6 and a widely deployed browser target.
What it is
Chrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a crafted HTML page corrupt the heap. It affects Chrome before 128.0.6613.84 and, per the vendor list, Microsoft Edge. Because it is a browser engine bug reachable from web content, it is a serious remote code execution risk.
Impact
An attacker who gets a victim to load a malicious page can corrupt heap memory in the renderer, which can lead to code execution in the browser's sandboxed process and, combined with a sandbox escape, full compromise.
Attack surface
Reached over the network by a crafted HTML page rendered in Chrome or Edge; no authentication is required, but the victim must visit or be directed to the page (UI:R).
Exploitation
Listed in CISA KEV since 2024-08-26 with a 2024-09-16 remediation due date, and a Microsoft advisory ties exploitation to the North Korean actor Citrine Sleet. EPSS 30-day probability is about 20.7% (97th percentile), so exploitation is confirmed and active.
What to do
- Update Chrome to 128.0.6613.84 or later and Edge to its corresponding patched build immediately.
- Enforce browser auto-update and verify versions across managed endpoints.
- Prioritize patching internet-facing and high-value users per the KEV due date of 2024-09-16.
- If patching is not possible, restrict or discontinue use of the affected browser per vendor and CISA guidance.
- Review and tighten browser isolation or sandboxing controls for users who must browse untrusted content.
Detection
- Hunt for Chrome or Edge processes spawning unexpected child processes or making anomalous network connections after web browsing.
- Monitor for crashes in the renderer or V8-related crash signatures on endpoints running unpatched browser versions.
- Check asset inventories for Chrome versions below 128.0.6613.84 and Edge builds lacking the corresponding fix.
- Correlate proxy or DNS logs for known Citrine Sleet infrastructure and exploit delivery patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-7971 to the Known Exploited Vulnerabilities catalog on 26 August 2024 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 16 September 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html | Release Notes |
| https://issues.chromium.org/issues/360700873 | Permissions Required |
| https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zer | ExploitPatchThird Party AdvisoryVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7971 | US Government Resource |
Track CVE-2024-7971 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-7971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.