CVE-2024-8904: Type Confusion in V8
Chromium: CVE-2024-8904 Type Confusion in V8
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8904?
CVE-2024-8904 has been classified with a high severity level due to a type confusion vulnerability in Chromium.
How do I fix CVE-2024-8904?
To fix CVE-2024-8904, users should update their Microsoft Edge or Google Chrome browsers to the latest version.
What software is affected by CVE-2024-8904?
CVE-2024-8904 affects Microsoft Edge (Chromium-based) and Google Chrome versions before 129.0.6668.58.
Can CVE-2024-8904 lead to remote code execution?
Yes, CVE-2024-8904 can potentially allow an attacker to execute arbitrary code on the affected systems.
How was CVE-2024-8904 discovered?
CVE-2024-8904 was discovered as a type confusion issue in the Chromium engine, prompting its disclosure by the Chrome team.