CVE-2024-12053

Published Dec 3, 2024

Last updated a year ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-12053 is a "Type Confusion" vulnerability found in the V8 JavaScript engine, which is a core component of Google Chrome and other Chromium-based web browsers, including Microsoft Edge. This flaw occurs when the program incorrectly handles the data type of a variable, leading to potential object corruption. A remote attacker could exploit this vulnerability by crafting a malicious HTML page. If a user visits such a page, the attacker could potentially exploit the type confusion to execute arbitrary code, thereby gaining unauthorized control over the system.

Description
Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Analyzed
Products
chrome

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

chrome-cve-admin@google.com
CWE-843
nvd@nist.gov
CWE-843
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-843

Social media

Hype score
Not currently trending
  1. Want to know how a “small” WebAssembly issue can become a big security problem? In our new article, SSD Labs researcher, Aaron Cho, analyzes CVE-2024-12053. An arbitrary WebAssembly type confusion vulnerability leading to an RCE. Read about it here: https://t.co/Ukk8GrGpzo

    @SecuriTeam_SSD

    29 Apr 2026

    2335 Impressions

    7 Retweets

    30 Likes

    21 Bookmarks

    0 Replies

    0 Quotes

  2. مرورگر ها به عنوان یکی از پرکاربردترین برنامه های سمت کلاینت ، می توانند دارای آسیب پذیری باشند . برای مرورگر Chrome آسیب پذیری با کد شناسایی CVE-2024-12053 منتشر شده است. این آسیب پذیری که در قسمت JavaScript engine مرورگر وجود دارد از نوع RCE می باشد. https://t.co/Poz3aKY03t h

    @AmirHossein_sec

    13 Dec 2024

    28 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Threat Alert: Google Chrome Addresses High-Severity Flaw in V8 JavaScript Engine (CVE-2024-120 CVE-2024-12053 Severity: 🔴 High Maturity: 💢 Emerging Learn more: https://t.co/OxGGogTs2L #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    5 Dec 2024

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Google Patches CVE-2024-12053 in Chrome #GoogleChrome #CVE-2024-12053 https://t.co/opZNDYDnHF

    @pravin_karthik

    4 Dec 2024

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Google Chrome Addresses High-Severity Flaw in V8 JavaScript Engine (CVE-2024-12053) https://t.co/YhP5WPZuAc

    @Dinosn

    4 Dec 2024

    1790 Impressions

    11 Retweets

    11 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  6. Google Chrome Addresses High-Severity Flaw in V8 JavaScript Engine Find out how #Google #Chrome's latest update enhances your security. Learn about the high-severity vulnerability (CVE-2024-12053) and how it can be patched https://t.co/nVWzT1k82l

    @the_yellow_fall

    4 Dec 2024

    189 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. (CVE-2024-12053)[379009132][$8000][wasm]Type Confusion "...Those relative types were leaking from the type canonicalizer, which leads to type confusion in callers..." https://t.co/MAFXr5x2qI https://t.co/pPnE14WOtg https://t.co/IyzPqoFNwP Reported by gal1ium and chluo

    @xvonfers

    4 Dec 2024

    1363 Impressions

    2 Retweets

    15 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2024-12053 Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity High) https://t.co/7VYy099qrt

    @VulmonFeeds

    3 Dec 2024

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. The severity is increased for this new vulnerability affecting Google Chrome (CVE-2024-12053) https://t.co/BJ1kfTC53s

    @vuldb

    3 Dec 2024

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2024-12053 Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium se… https://t.co/QTobYuDFes

    @CVEnew

    3 Dec 2024

    417 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

Configurations