Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +2 more
- < 134.0.6998.35
A high-severity out-of-bounds read vulnerability has been identified in the V8 JavaScript engine used by Google Chrome. This issue affects Chrome versions prior to 134.0.6998.35. The vulnerability allows remote attackers to perform out-of-bounds memory access by exploiting a crafted HTML page.
Exploitation of this vulnerability leads to memory corruption, which can commonly be leveraged to execute arbitrary code in the context of the affected process.
The vulnerability can be reproduced using a component build of V8. After setting the denormal flushing flag, the crafted JavaScript payload triggers the out-of-bounds read, causing a debug check failure due to an invalid memory access index.
Users should update to Google Chrome version 134.0.6998.35 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.