●Chrome セキュリティ · 2024年5月

Google Chrome セキュリティ勧告:V8 JIT & WebRTC

悪用が確認された V8 JIT コンパイラの型混同脆弱性を修正する Google Chrome 緊急セキュリティアップデートの技術解説。

1
Active Zero-Day (V8)
8.8
CVSS Severity
Critical
Browser Exploitation
Immediate
Fleet Patch Urgency

セキュリティトリアージとリスク評価

Google has released an emergency security update for Chrome across Windows, Mac, and Linux to patch CVE-2024-4947, an actively exploited type confusion vulnerability in the V8 JavaScript engine. This flaw allows malicious web pages to escape the V8 sandbox and execute arbitrary code in the browser renderer process.

優先脆弱性トリアージマトリックス

CVE識別番号 対象サブシステム / コンポーネント 影響範囲 CVSS ゼロデイ悪用確認?
CVE-2024-4947V8 JavaScript EngineJIT Type Confusion8.8 HighYES (In-The-Wild)
CVE-2024-4948Dawn / WebGPUUse-After-Free8.1 HighNo
CVE-2024-4949V8 WebAssemblyOut-of-Bounds Memory Access7.5 HighNo
CVE-2024-4950Downloads SubsystemInappropriate Implementation4.3 MediumNo
FEATURED CODE TEARDOWN

Deep Dive: CVE-2024-4947 Chrome V8 Turbofan Type Confusion Teardown →

Examine the exact C++ Git commit from Chromium Gerrit showing how property accessor prototype transitions fooled the Turbofan optimizer.

← Browse Full Security Directory Explore All Source Teardowns →