CVE-2024-7971 is a type-confusion vulnerability in Chromium's V8 JavaScript and WebAssembly engine affecting Google Chrome and Chromium versions before 128.0.6613.84. A remote attacker can trigger heap corruption through a crafted HTML page, potentially obtaining arbitrary code execution in the sandboxed renderer process. The vulnerability was exploited as a zero-day, including in attacks attributed with medium confidence to the North Korean threat actor Citrine Sleet. Google released a fix on August 21, 2024.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains four files: a GitHub Pages .nojekyll marker, disclosure and verification documentation in README.md, a styled verification interface in index.html, and the standalone trigger implementation in poc-core.js. Their listed sizes total 23,226 bytes; the original repository URL, git reference, and archive size were not supplied. The core exports CVE7971DOS in browsers and a CommonJS API for Node-based smoke testing. It constructs a small WebAssembly module, patches one floating-point immediate, imports a JavaScript callback and mutable global, and calls the exported main function. The documented defect is V8 Liftoff failing to spill all loop inputs before entering a loop, associated with fix commit 979757648854. On the claimed vulnerable arm64 build, the callback receives a malformed tagged value whose inspection can crash the renderer. A callback counter throws a normal JavaScript exception to terminate surviving runs. The wrapper displays browser identification and logs, documents automatic triggering, and exposes control, crash, desktop-x64, repeated-crash, multi-tab, stop, and evidence-copy controls. Visible handlers navigate to loop URLs and open additional tabs. LocalStorage markers retain trigger and loop state across page loads, so the README's blanket statement of no persistence is too broad: there is browser-local state, although no operating-system persistence mechanism is shown. No telemetry, exfiltration destination, or external service request appears in the supplied code; the page loads its relative core script. Important limitations: index.html is explicitly truncated, so its complete query parsing, stop handling, and crash-detection logic cannot be audited. The supplied MODES definitions give control and crash-x64 identical f32 and global bit patterns, so the x64 label does not select a distinct core payload and its claimed behavior is architecture-dependent rather than separately implemented. The code was not executed, and the claimed device results and fixed-version boundary remain repository assertions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A V8 JavaScript-engine type-confusion vulnerability in the outdated Chromium/CEF browser component bundled with OBS Studio. When chained with XSS in an unsafe custom Twitch chat overlay, it can enable native code execution on a streamer's Windows PC.
Chromium-family browser vulnerability; technical details are not supplied.
Unknown (only referenced as a related post title; no vulnerability details provided in the content).
A Chromium remote code execution zero-day caused by a type confusion issue in the V8 JavaScript and WebAssembly engines, used to help deliver FudModule.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.