실제 공격에 악용된 V8 JIT 컴파일러 타입 혼동 취약점을 해결한 Chrome 긴급 안정화 채널 업데이트 분석.
CVE-2024-4947, an actively exploited type confusion vulnerability in the V8 JavaScript engine. This flaw allows malicious web pages to escape the V8 sandbox and execute arbitrary code in the browser renderer process.
| CVE 식별자 | 서브시스템 / 구성 요소 | 영향 | CVSS | 실제 악용 여부? |
|---|---|---|---|---|
CVE-2024-4947 | V8 JavaScript Engine | JIT Type Confusion | 8.8 High | YES (In-The-Wild) |
CVE-2024-4948 | Dawn / WebGPU | Use-After-Free | 8.1 High | No |
CVE-2024-4949 | V8 WebAssembly | Out-of-Bounds Memory Access | 7.5 High | No |
CVE-2024-4950 | Downloads Subsystem | Inappropriate Implementation | 4.3 Medium | No |
Examine the exact C++ Git commit from Chromium Gerrit showing how property accessor prototype transitions fooled the Turbofan optimizer.