KEV · Actively exploited
CVE-2024-7971
CVE-2024-7971 is actively exploited (CISA KEV catalog) : critical severity (CVSS 9.6), 3 tracked apps concerned, none still exposed on their current version.
- Severity (CVSS)
- 9.6
- Exploitation
- Confirmed
- Tracked apps
- 3
- Still exposed
- 0
NVD scale
CISA KEV · EPSS predicts 21.1 %
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS
21.10%
predictive model; CISA confirms active exploitation
percentile 97.5%
CISA Known Exploited Vulnerability
- Added to KEV
- 2024-08-26
- Remediation deadline
- 2024-09-16
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Ransomware
- Unknown (not documented by CISA)
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
-
-
Observed affected builds (56)
127.0.2651.105 127.0.2651.98 127.0.2651.86 127.0.2651.74 126.0.2592.113 126.0.2592.102 126.0.2592.87 126.0.2592.81 126.0.2592.68 126.0.2592.61 126.0.2592.56 125.0.2535.92 125.0.2535.67 125.0.2535.51 124.0.2478.109 124.0.2478.105 124.0.2478.97 124.0.2478.80 124.0.2478.67 124.0.2478.51 123.0.2420.97 123.0.2420.81 123.0.2420.65 122.0.2365.92 122.0.2365.80 122.0.2365.66 122.0.2365.59 122.0.2365.52 121.0.2277.128 121.0.2277.112 +26 · see history
Vulnerable CPE configurations (3)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <128.0.6613.84 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <128.0.6613.84 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
| microsoft |
edge All platforms (wildcard)
|
All platforms (wildcard) | <128.0.2739.42 | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.