Vulnerability Intelligence Report
Google Chromium V8 Type Confusion Vulnerability
CVE-2024-5274
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
8.3
HIGH
Exploitability:1.7
Impact Score:6.1
EPSS Probability:10.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-843 ↗CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Chrome | 125.0.6422.112 < 125.0.6422.112 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
EPSS Score
10.020%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Chrome · Vendor · USA |
| Reserved | 2024-05-23T16:20:01 |
| Published | 2024-05-28T14:44:31 |
| Last Updated | 2025-10-21T23:05:17 |
Community Chatter & Buzz