CVE-2024-0519Active Exploitation(couchbase / chrome)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch couchbase chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-02-07. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787CWE-125

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • couchbase_server
  • fedora

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-01); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Products
chromecouchbase_serverfedora

2 versions affected across 3 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-16: 1Mentions · 2026-04-08: 1Mentions · 2026-04-13: 1Mentions · 2026-05-01: 2Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-01: 1Exploit Tool / Code · 2026-05-01: 1Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-05-01: 1Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-16: 1Technical Details · 2026-04-13: 1Technical Details · 2026-05-01: 102-1604-0804-1305-0105-15
Signal classification3 categories
Active Exploitation
350.0%
General
233.3%
Disclosure
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-161
Active Exploitation1
2026-04-081
General1
2026-04-131
Active Exploitation1
2026-05-012
Active Exploitation1Disclosure1
2026-05-151
General1
Full discourse6 posts
  • j j@mistymntncop
    General

    Very cool! Congrats Mythos on solving CVE-2024-0519 :-). https://exploitbench.ai/blog/human-observations/

    Post summary

    The post simply congratulates Mythos for resolving CVE‑2024‑0519, lacking technical specifics, exploit code, patch info, or evidence of active exploitation.

    51211076510.2K
    3.0K followersView on X
  • eyitemi@eeyitemi
    General

    Today is a good day to remind you all of CVE-2024-0519.

    Post summary

    The statement merely references CVE-2024-0519 without providing any additional technical details or context.

    00022459
    6.1K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2024-0519 Exploit in the wild confirmed for CVE-2024-0519 (CVSS null). Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allo... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    Exploit of CVE-2024-0519 has been confirmed in the wild, targeting an out‑of‑bounds memory access flaw in the Google Chromium V8 Engine, with no mention of patches or PoC.

    00101371
    5.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-0519: Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium,…

    Post summary

    The text reports CVE-2024-0519 as an out‑of‑bounds heap corruption vulnerability in the Chromium V8 engine, noting the potential for exploitation via crafted HTML, but provides no proof‑of‑concept, exploit code, active attacks, or remediation details.

    1000067
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-0519-chromium-v8 #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked research paper reports an active exploitation of CVE‑2024‑0519 in Chromium V8, providing a PoC with exploit details, but it does not discuss any patch or mitigation.

    0000044
    152 followersView on X
  • 趣テクノロジー@omomuki_tech
    Active Exploitation

    Google Chromeに、今年初めて実世界での悪用が確認されたゼロデイ脆弱性(CVE-2024-0519)が発見され、これを修正する緊急のセキュリティアップデートがリリースされました。 この脆弱性は、ChromeのJavaScriptエンジンである「V8」に存在する「境界外メモリアクセス」の欠陥です。 攻撃者は、ユーザーに特別に細工された悪意のあるHTMLページを閲覧させることで、プログラムが本来アクセスしてはいけないメモリ領域にアクセスし、情報を盗んだり、任意のコードを実行したりする可能性があります。 Googleは、この脆弱性を悪用した攻撃がすでに行われていることを認めており、脅威の深刻度は「高」と評価されています。 この問題に対処するため、Windows、Mac、Linux向けに緊急アップデート(バージョン120.0.6099.224/225など)が提供されています。 Chromeブラウザを再起動することでアップデートが適用されるため、全てのユーザーは速やかに対応することが強く推奨されます。 #Chrome #セキュリティ #脆弱性 https://www.bleepingcomputer.com/news/security/google-patches-first-chrome-zero-day-exploited-in-attacks-this-year/

    Post summary

    CVE‑2024‑0519, an out‑of‑bounds memory access flaw in Chrome’s V8 engine, was actively exploited in the wild early this year, prompting Google to release an emergency patch and urging users to update immediately.

    0000099
    215 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcouchbasecouchbase_server---
OSfedoraprojectfedora38--
OSfedoraprojectfedora39--
Appgooglechrome---

Explore more