
CVE-2024-7965是Google Chrome浏览器中V8 JavaScript引擎的一个高危漏洞。该漏洞源于V8引擎在处理特定JavaScript代码时实现不当,导致堆内存损坏。攻击者可通过诱导用户访问包含特制JavaScript的恶意网页,利用此漏洞在Chrome渲染器中执行任意代码。
CVE-2024-7965 is a high-severity vulnerability in the V8 JavaScript engine of the Google Chrome browser. The vulnerability stems from improper implementation in the V8 engine when handling specific JavaScript code, leading to heap memory corruption. An attacker could exploit this vulnerability by luring users into visiting a malicious webpage containing specially crafted JavaScript, allowing arbitrary code execution in the Chrome renderer. Successful exploitation could result in browser crashes, information disclosure, or even complete control over the victim's browser environment. The vulnerability has a CVSS score of 8.8, indicating its high severity.
It is worth noting that CVE-2024-7965 primarily affects devices running the ARM64 architecture, including Apple laptops released after November 2020 and all versions of Android smartphones. Therefore, affected users should update Chrome to version 128.0.6613.84 or later as soon as possible to mitigate potential attack risks.