CVE-2024-2887

Published Mar 26, 2024

Last updated a year ago

CVSS high 7.7
Google Chrome
WebAssembly

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-2887 is a type confusion vulnerability found in WebAssembly in Google Chrome versions prior to 123.0.6312.86. It can be triggered by a remote attacker who crafts a malicious HTML page. The vulnerability stems from how WebAssembly handles recursive type groups, which can lead to exceeding the maximum number of declared heap types and create opportunities for type confusion. Successful exploitation of CVE-2024-2887 allows a remote attacker to execute arbitrary code. This can lead to arbitrary read/write within the V8 memory sandbox, the ability to obtain addresses of JavaScript objects, and manipulation of object pointers. It was demonstrated at the Pwn2Own Vancouver 2024 hacking competition. Google patched this vulnerability in Chrome version 123.0.6312.86.

Description
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Modified
Products
chrome, fedora

Risk scores

CVSS 3.1

Type
Primary
Base score
7.7
Impact score
6
Exploitability score
1
Vector string
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-843
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-843

Social media

Hype score
Not currently trending
  1. Seven out of sixteen is still ugly. OpenPatcher-S1 scored 7/16 on the public ExploitBench CVE-2024-2887 target. The listed baselines scored 3, 2, and 2. It more than doubled the strongest one. Nine rungs remain unsolved. Reproduce it.

    @jperla

    14 Aug 2026

    256 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Want to learn about Chrome exploitation and the role of WebAssembly in it? In our new article, we'll break down the world of WASM, how it interacts with V8, and use CVE-2024-2887 as a case study to show how flaws in WASM can lead to RCE. Read it here: https://t.co/Ojli05dmZx

    @SecuriTeam_SSD

    5 Aug 2025

    36425 Impressions

    12 Retweets

    48 Likes

    33 Bookmarks

    0 Replies

    0 Quotes

  3. Want to learn about Chrome exploitation and the role of WebAssembly in it? In our new article, we'll break down the world of WASM, how it interacts with V8, and use CVE-2024-2887 as a case study to show how flaws in WASM can lead to RCE. Read it here: https://t.co/Ojli05dmZx

    @SecuriTeam_SSD

    17 Jul 2025

    21828 Impressions

    0 Retweets

    17 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  4. Want to learn about Chrome exploitation and the role of WebAssembly in it? In our new article, we'll break down the world of WASM, how it interacts with V8, and use CVE-2024-2887 as a case study to show how flaws in WASM can lead to remote code execution. Read it here:

    @SecuriTeam_SSD

    16 Jul 2025

    37562 Impressions

    10 Retweets

    57 Likes

    44 Bookmarks

    1 Reply

    1 Quote

  5. La vulnerabilidad CVE-2024-2887 en Google Chrome https://t.co/zlboHsOhfu #SeguridadInformatica

    @f3nixh4ck

    10 May 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Check out my latest article: 🚨 Critical Chrome Vulnerability: CVE-2024-2887 https://t.co/ixfjr2NKv7 via @LinkedIn

    @Yogeshwaran2022

    19 Oct 2024

    28 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations