← לוח פגיעויות

CVE-2024-7971

קריטית 9.6 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Google Chromium V8 Type Confusion Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

מדדים

CVSS 3.1
9.6 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
19% (אחוזון 100) נכון ל-26/7/2026
CWE
CWE-843

מוצרים מושפעים

google: chrome; microsoft: edge

קישורים