CVE-2024-7965 Details
Description
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
A vulnerability in the V8 JavaScript engine of Google Chrome has been identified, allowing remote attackers to exploit heap corruption through a crafted HTML page. This issue affects Google Chrome versions prior to 128.0.6613.84, as well as other browsers that use the Chromium engine, such as Microsoft Edge and Opera. The vulnerability arises from an inappropriate implementation in V8, specifically in the Turboshaft compiler, where the optimization of certain instructions can be manipulated, leading to memory corruption. This flaw has been exploited in the wild, with reports indicating its use in ransomware campaigns.
Users should update to Google Chrome version 128.0.6613.84 or later, where this vulnerability has been fixed. For ChromeOS, the update is already available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 31, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7965 | CISA-ADP | US Government Resource |
| https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html | [email protected] | Release Notes |
| https://issues.chromium.org/issues/356196918 | [email protected] | Permissions Required |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Google Chromium V8 Inappropriate Implementation Vulnerability | Aug 28, 2024 | Sep 18, 2024 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-358 | Improperly Implemented Security Check for Standard | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google chrome | < 128.0.6613.84 |
CPE
Remediation
| |
| microsoft edge chromium | < 128.0.2739.42 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 24, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Sep 18, 2024 | Reanalysis | [email protected] |
| Aug 29, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Aug 26, 2024 | Initial Analysis | [email protected] |
| Aug 22, 2024 | CVE Modified | CISA-ADP |
| Aug 21, 2024 | New CVE Received | [email protected] |