CVE-2024-7971

Published Aug 21, 2024

Last updated a year ago

Exploit knownCVSS critical 9.6
Google Chrome
web application
Zero-day

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-7971 is a type confusion vulnerability found in the V8 JavaScript and WebAssembly engine within Google Chrome versions prior to 128.0.6613.84. This flaw allows a remote attacker to potentially exploit heap corruption through a crafted HTML page. The vulnerability stems from the Liftoff compiler's handling of loop structures during WebAssembly (WASM) JIT compilation, where it doesn't enforce strict type checks, potentially leading to memory corruption. It has been reported that this vulnerability has been exploited in the wild.

Description
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Analyzed
Products
chrome, edge

Risk scores

CVSS 3.1

Type
Primary
Base score
9.6
Impact score
6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Google Chromium V8 Type Confusion Vulnerability
Exploit added on
Aug 26, 2024
Exploit action due
Sep 16, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

chrome-cve-admin@google.com
CWE-843
nvd@nist.gov
CWE-843
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-843

Social media

Hype score
Not currently trending
  1. Multiple Chinese APT groups coordinated deployment of the BlueMoon exploit kit, chaining three zero-days (CVE-2024-7971, CVE-2024-8198, CVE-2024-38063) for browser compromise and Windows privilege escalation. Post-compromise lateral movement across targeted aerospace and defense

    @aviatrixtrc

    11 Sept 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 【ITニュース】GoogleがChromeブラウザの重大な脆弱性を確認し、緊急アップデートを公開。CVE-2024-7971として追跡され、既に悪用が確認されているゼロデイ脆弱性。type confusionの脆弱性で、攻撃者が細工したWebペ

    @nespe_shacho

    10 Sept 2026

    99 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 【ITニュース】GoogleがChromeの脆弱性を悪用した攻撃を確認し、緊急パッチをリリース。CVE-2024-7971として深刻度「High」で公開され、タイプコンフュージョンの脆弱性が存在。ゼロデイ攻撃が既に観測されており

    @nespe_shacho

    5 Sept 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Attackers exploited CVE-2024-7971, a V8 type confusion vulnerability in Chrome, to achieve code execution through crafted HTML pages. This zero-day enabled arbitrary read/write access to JavaScript heap, potentially allowing sandbox escape and endpoint compromise. 🔗 Full TRC

    @aviatrixtrc

    4 Sept 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 【ITニュース】Googleが8/31、Chromeに緊急パッチを公開。ゼロデイ脆弱性(CVE-2024-7971)が実際の攻撃で悪用され、全ユーザーに即時更新を推奨。Type Confusionというメモリ破損の脆弱性で、攻撃者が任意コード実行可

    @nespe_shacho

    1 Sept 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 普段使ってるChromeとEdge、実は今すぐ更新が必要です。7月8日に発表されたゼロデイ脆弱性(CVE-2024-7971)、もう悪用されてるって。 普通のWebサイト見てるだけで感染する可能性があるのでヤバい案件。 設定から

    @jun1yamam0t0

    8 Jul 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 2025-04-13 の人気記事はコチラでした。(自動ツイート) #Hacker_Trends ――― CVE-2024-7971/poc.js at main · mistymntncop/CVE-2024-7971 · GitHub https://t.co/cFDt3drj5N https://t.co/CWCx7fASTs

    @motikan2010

    14 Apr 2025

    144 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. My writeup for CVE-2024-7971. Just a POC. Let me know if u have any questions. https://t.co/dAEjUYoPls

    @mistymntncop

    12 Apr 2025

    9392 Impressions

    38 Retweets

    164 Likes

    86 Bookmarks

    6 Replies

    1 Quote

  9. CVE-2024-7971、KEVあるんか

    @abdda149

    9 Mar 2025

    16 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Top 5 Trending CVEs: 1 - CVE-2024-50379 2 - CVE-2024-38200 3 - CVE-2024-12856 4 - CVE-2023-48788 5 - CVE-2024-7971 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    30 Dec 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Version 124.0.6327.3 is significantly outdated. https://t.co/zy62zi4JHz CVE-2024-4058: A critical type confusion vulnerability in ANGLE (WebGL component) that could allow heap corruption exploitation through crafted HTML pages. CVE-2024-7971: A high-severity type confusion in…

    @gnukeith

    24 Dec 2024

    1226 Impressions

    3 Retweets

    33 Likes

    4 Bookmarks

    2 Replies

    1 Quote

  12. North Korean hackers exploit Chrome zero-day to deploy rootkit North Korean hackers have exploited a recently patched Google Chrome zero-day (CVE-2024-7971) to deploy the FudModule rootkit after gaining SYSTEM privileges using a Windows Kernel exploit.... https://t.co/IcYuqpf5zq

    @SecurityAid

    13 Dec 2024

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🔴 #Google #Chrome, Type Confusion Vulnerability, #CVE-2024-7971 (Critical) - Critical https://t.co/aIw2VP7zR2

    @dailycve

    27 Nov 2024

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Actively exploited CVE : CVE-2024-7971

    @transilienceai

    24 Nov 2024

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. 🚨 Zero-Day Alert! 🚨North Korean threat actor Citrine Sleet is back, exploiting a zero-day vulnerability (CVE-2024-7971) in Chromium, targeting #Cryptocurrency institutions.💰 Book your #Demo now: https://t.co/lGRc2vih4Q https://t.co/yO6eYeNAIK

    @Akitra_Inc

    21 Oct 2024

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations