CVE-2024-1939

Published Feb 29, 2024

Last updated 2 years ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-1939 is a type confusion vulnerability found in the V8 JavaScript engine used by Google Chrome. This flaw affects Chrome versions released prior to 122.0.6261.94. A remote attacker could potentially exploit this vulnerability by crafting a malicious HTML page, which could lead to heap corruption. The issue also impacts users of the Chromium web browser in Fedora 38 and Fedora 39.

Description
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Analyzed
Products
chrome, fedora

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-843
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-843

Social media

Hype score
Not currently trending

Configurations