CVE-2024-5274 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CISA has confirmed active exploitation in the wild. EPSS estimates a 10.02% chance of exploitation in the next 30 days.

## Description

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

## Metrics

CVSS 3.19.6/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS Probability 10.02%

95.0th percentile

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Exploitation Status

This vulnerability is listed in CISA’s [Known Exploited Vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) catalog, confirming active exploitation in the wild. Federal agencies must remediate by Jun 18, 2024.

## Weakness Enumeration

- [CWE-843](https://cwe.mitre.org/data/definitions/843.html)
- [CWE-843](https://cwe.mitre.org/data/definitions/843.html)

## Affected Software

| Vendor          | Product | Versions               |
|-----------------|---------|------------------------|
| Google          | Chrome  | < 125.0.6422.112      |
| Fedoraproject   | Fedora  | 39                     |
| Fedoraproject   | Fedora  | 40                     |

## References

- [Release Notes](https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html)
- [Exploit, Issue Tracking](https://issues.chromium.org/issues/341663589)
- [Mailing List](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVC3FNI7HZLVSRIFBVUSBHI233DZYBKP/)
- [Mailing List](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T6IBUYVPD4MIFQNNYBGAPI5MOECWXXOB/)
- [US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-5274)

## Timeline

Published May 28, 2024

Last Modified Jun 17, 2026

Status Analyzed

## Frequently Asked Questions

**What is CVE-2024-5274?**

**How severe is CVE-2024-5274?**

CVE-2024-5274 has a CVSS score of 9.6/10 (CRITICAL severity). The EPSS model estimates a 10.02% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.

**How do I fix CVE-2024-5274?**

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
