CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-0519

Critical Severity|Google
82
SVRS
8.8
CVSSv3
0.03769
EPSS
TAGS
In The WildExploit AvaliableCISA KEV
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:RS:UC:HI:HA:H
PUBLICATION DATE2024-01-16
LAST MODIFIED2025-10-21

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-0519, is an out-of-bounds memory access flaw found in the V8 JavaScript engine within Google Chrome. It matters because it allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a specially crafted HTML page. Successful exploitation could lead to arbitrary code execution or denial of service, compromising the integrity and confidentiality of the affected system. This issue is rated with a Chromium security severity of High.
2. What are the CVSS score, severity level, and disclosure details?
  • CVSS Score: 8.8
  • Severity Level: High (based on Chromium security severity rating and CVSS score)
  • Disclosure Details:
    • Published: 2024-01-16 21:14:49
    • Modified: 2025-10-21 23:05:28
3. Which products, vendors, systems, and versions are affected?
  • Vendor: Google
  • Product: Google Chrome
  • Component: V8 JavaScript engine
  • Affected Versions: All versions of Google Chrome prior to 120.0.6099.224 are vulnerable.
4. What is the technical root cause and attack vector?
  • Technical Root Cause: The root cause is an out-of-bounds memory access within the V8 JavaScript engine. This type of flaw, categorized under CWE-787 (Out-of-bounds Write) and CWE-125 (Out-of-bounds Read), allows an attacker to read from or write to memory locations outside the intended buffer. In this specific case, it leads to heap corruption.
  • Attack Vector: The attack vector is remote. Exploitation occurs via a crafted HTML page, meaning an attacker can deliver the malicious content through a website that a user visits.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by a remote attacker who crafts a malicious HTML page. When a user running a vulnerable version of Google Chrome navigates to or loads this crafted page, the out-of-bounds memory access in the V8 engine is triggered. This can corrupt the heap memory, which can subsequently be leveraged by the attacker to execute arbitrary code within the context of the browser.
6. What mitigation steps and patches are available?

The primary mitigation step is to update Google Chrome to a patched version.

  • Patch Availability: Google Chrome version 120.0.6099.224 and later versions contain the patch that resolves this vulnerability.
  • Recommended Action: Users and administrators should update their Google Chrome installations immediately to version 120.0.6099.224 or a newer available version to eliminate the vulnerability.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by checking the installed version of the Google Chrome browser. Any installation of Google Chrome with a version number earlier than 120.0.6099.224 is considered vulnerable to CVE-2024-0519. This can typically be checked within the browser's "About Chrome" section.
10. What public intelligence references and advisories exist?
  • CVE Identifier: CVE-2024-0519
  • Chromium Security Advisory: The vulnerability is referenced in Chromium's security advisories with a "High" severity rating.
11. What is the risk assessment and urgency level?
  • Risk Assessment: The risk associated with CVE-2024-0519 is significant. With a CVSS score of 8.8 and a Chromium security severity of High, this vulnerability presents a critical threat. The potential for heap corruption via a crafted HTML page means a remote attacker can compromise affected systems without requiring complex interaction beyond a user visiting a malicious website.
  • Urgency Level: The urgency level for patching and mitigation is High. The presence of published active exploits indicates that this vulnerability is actively being targeted in the wild. Immediate action to update all affected Google Chrome installations is strongly recommended to prevent potential system compromise and data loss.

No IOCs found for this CVE

TitleSoftware LinkDate
Oxdestiny/CVE-2024-0519-Chrome-exploithttps://github.com/Oxdestiny/CVE-2024-0519-Chrome-exploit2024-03-27
JohnHormond/CVE-2024-0519-Chrome-exploithttps://github.com/JohnHormond/CVE-2024-0519-Chrome-exploit2024-03-04
Google Chromium V8 Out-of-Bounds Memory Access Vulnerabilityhttps://www.cisa.gov/search?g=CVE-2024-05192024-01-17
Threekiii/CVEhttps://github.com/Threekiii/CVE2023-01-05
Ostorlab/KEVhttps://github.com/Ostorlab/KEV2022-04-19
SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

avatar
Lyrie.ai@lyrie_ai
2026-05-01
CVE-2024-0519: Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium,…
avatar
CTIWatch@ctiwatchcloud
2026-04-13
🚨 [HIGH] Active exploitation detected: CVE-2024-0519 Exploit in the wild confirmed for CVE-2024-0519 (CVSS null). Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allo... 🔗 https://t.co/RZBhpWnHFz #ZeroDay #ExploitInWild #CyberSecurity
avatar
eyitemi@eeyitemi
2026-04-08
Today is a good day to remind you all of CVE-2024-0519.
avatar
j j@mistymntncop
2026-02-21
@streypaws CVE-2024-0519 it's under perpetual embargo unfortunately :'(...
Configuration 1
TypeVendorProduct
AppGooglechrome
Configuration 2
TypeVendorProduct
OSFedoraprojectfedora
Configuration 3
TypeVendorProduct
AppCouchbasecouchbase_server
ReferenceLink
AF854A3A-2127-422B-91AE-364DA2661108https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
AF854A3A-2127-422B-91AE-364DA2661108https://crbug.com/1517354
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/IIUBRVICICWREJQUVT67RS7E4PVZQ5RS/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/TNN4SO5UI3U3Q6ASTVT6WMZ4723FYDLH/
[email protected]https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
[email protected]https://crbug.com/1517354
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/IIUBRVICICWREJQUVT67RS7E4PVZQ5RS/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/TNN4SO5UI3U3Q6ASTVT6WMZ4723FYDLH/
[email protected]https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
[email protected]https://crbug.com/1517354
[email protected]https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
[email protected]https://crbug.com/1517354
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/IIUBRVICICWREJQUVT67RS7E4PVZQ5RS/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/TNN4SO5UI3U3Q6ASTVT6WMZ4723FYDLH/
[email protected]https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
[email protected]https://crbug.com/1517354
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/IIUBRVICICWREJQUVT67RS7E4PVZQ5RS/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/TNN4SO5UI3U3Q6ASTVT6WMZ4723FYDLH/
[email protected]https://www.couchbase.com/alerts/
AF854A3A-2127-422B-91AE-364DA2661108https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
AF854A3A-2127-422B-91AE-364DA2661108https://crbug.com/1517354
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/IIUBRVICICWREJQUVT67RS7E4PVZQ5RS/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/TNN4SO5UI3U3Q6ASTVT6WMZ4723FYDLH/
AF854A3A-2127-422B-91AE-364DA2661108https://www.couchbase.com/alerts/
[email protected]https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
[email protected]https://crbug.com/1517354
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/IIUBRVICICWREJQUVT67RS7E4PVZQ5RS/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/TNN4SO5UI3U3Q6ASTVT6WMZ4723FYDLH/
[email protected]https://www.couchbase.com/alerts/
CWE IDCWE NameDescription
CWE-787Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.
CWE-125Out-of-bounds ReadThe software reads data past the end, or before the beginning, of the intended buffer.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.