Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
https://thehackernews.com/2024/08/north-korean-hackers-deploy-fudmodule.html
https://thehackernews.com/2024/08/google-fixes-high-severity-chrome-flaw.html
https://www.darkreading.com/vulnerabilities-threats/patch-now-google-zero-day-exploit
https://github.com/l1m3syc/CVE-2024-4947-PoC
https://github.com/DiabloX90911/CVE-2024-4947
https://github.com/bjrjk/CVE-2024-4947
https://github.com/uixss/PoC-CVE-2024-4947
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4947
https://issues.chromium.org/issues/340221135
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html
Published: 2024-05-15
Updated: 2025-10-24
Named Vulnerability: GHSA-p8v3-5hqq-7c5rKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.6
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity: Critical
EPSS: 0.15111