CVE-2024-6100

Published Jun 20, 2024

Last updated 2 years ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-6100 is a "Type Confusion" vulnerability found in the V8 JavaScript engine, which is a core component of Google Chrome. This flaw occurs when a program allocates or initializes a resource with one data type but then attempts to access it using an incompatible type. This discrepancy can lead to unexpected behavior within the software. Exploitation of CVE-2024-6100 can be achieved by a remote attacker who crafts a malicious HTML page. If a user running a vulnerable version of Google Chrome (specifically, versions prior to 126.0.6478.114) visits this specially designed page, the type confusion error in the V8 engine can be triggered. This allows the attacker to execute arbitrary code within the context of the browser.

Description
Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Modified
Products
chrome

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-843
chrome-cve-admin@google.com
CWE-843
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-843

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

14

Configurations