← לוח פגיעויות

CVE-2024-4947

קריטית 9.6 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Google Chromium V8 Type Confusion Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

מדדים

CVSS 3.1
9.6 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
15% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-843

מוצרים מושפעים

google: chrome; fedoraproject: fedora

קישורים