CVE-2024-0519: Out of bounds memory access in V8
Chromium: CVE-2024-0519 Out of bounds memory access in V8
Other sources
Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
— CISA
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 120.0.6099.234 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 120.0.6099.224 - Compensating control
Discontinue use of the product if vendor mitigations are unavailable for affected Chromium-based browsers (for example: Google Chromium, Microsoft Edge, Microsoft Edge Beta).
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-0519?
CVE-2024-0519 has been classified as a critical vulnerability that may allow for remote code execution.
How do I fix CVE-2024-0519?
To fix CVE-2024-0519, users should update Google Chrome to version 120.0.6099.234 or higher.
Which software is affected by CVE-2024-0519?
CVE-2024-0519 affects Google Chrome and Microsoft Edge (Chromium-based) up to specific versions as well as various versions of Couchbase Server and Fedora.
Is CVE-2024-0519 being actively exploited?
Yes, Google has acknowledged that CVE-2024-0519 is being actively exploited in the wild.
What is the impact of CVE-2024-0519 on users?
The impact of CVE-2024-0519 could include unauthorized access to sensitive information and potential system compromise.