CVE-2024-7965 is an inappropriate implementation of security mechanisms in the V8 JavaScript and WebAssembly engine used by Chromium-based browsers. Google Chrome versions before 128.0.6613.84 on Linux and before 128.0.6613.84/.85 on Windows and macOS can be induced to corrupt heap memory when processing crafted HTML content. The vulnerability has been exploited in the wild.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a minimal proof-of-concept for CVE-2024-7965 targeting Google Chrome’s V8 engine, with emphasis (per README) on ARM64 devices. Structure is simple: README.md (Chinese description of the vulnerability and affected versions), LICENSE (Apache-2.0), .gitignore, and a single PoC file poc.js. The PoC (poc.js) is a standalone JavaScript program with three main parts: (1) initializeArrays() creates a normal JS Array and a Uint32Array used as controlled numeric inputs; (2) demonstratePoc() builds a complex, branch-heavy loop intended to influence TurboFan’s type/range analysis and phi-node behavior, then uses a computed index to write into a small array (outOfBoundsArray) via outOfBoundsArray[index] = 0x500, aiming to produce an out-of-bounds write/heap corruption condition; (3) main() repeatedly calls demonstratePoc() in a loop (2..0x4ff) to encourage JIT optimization, then calls it with a specific value (7*5) and prints the returned values. No network communication, external URLs, IPs/domains, filesystem paths, or registry interactions are present. The code does not deliver a post-exploitation payload (no shellcode, no command execution); it is a trigger-style PoC meant to demonstrate/approximate the vulnerability condition under a vulnerable V8 build.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-7965, a vulnerability in the V8 JavaScript engine that affects ARM64 devices. The repository consists of two files: a README.md providing a brief description and attribution, and poc.js, which contains the exploit code. The JavaScript code in poc.js demonstrates manipulation of array indices and values to trigger an out-of-bounds (OOB) access condition, which is a common primitive for further exploitation such as arbitrary code execution or memory corruption. The PoC is designed to be run in an environment where the V8 engine is present and vulnerable, specifically on ARM64 architecture. No network, file, or registry endpoints are present in the code, and the exploit does not provide a payload or post-exploitation functionality. Its primary purpose is to demonstrate the presence of the vulnerability and provide a starting point for further research or exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chromium-family browser vulnerability; technical details are not supplied.
A zero-day vulnerability in Chromium’s V8 engine that has been exploited in the wild and for which exploit code exists. It was acknowledged by Google as being exploited after the initial patch release in August 2024.
Improper implementation of security mechanisms in Chrome's V8 component that can allow a remote unauthenticated attacker to bypass security features and execute malicious code via specially crafted web content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.