CVE-2024-5274Active Exploitation(fedoraproject / chrome)

MEDIUMCVSS 9.6 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fedoraproject chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-06-18. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • fedora

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
chromefedora

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-18: 1Active Exploitation · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 108-18
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • ZeroDayDev@ZeroDayDevApp
    Active Exploitation

    CISA added CVE-2024-5274 to the KEV catalog after confirming active exploitation. The flaw is a critical deserialization bug in Ray, the Python-native distributed compute framework used to scale ML/AI workloads. Untrusted data hits the jobs API, arbitrary code runs in the cluster. Ray is infrastructure for training and serving models at scale. If you're running it internet-exposed without auth, you're one HTTP request away from full cluster compromise. Patch or isolate before public exploits catch up to what attackers already have. https://nvd.nist.gov/vuln/detail/CVE-2024-5274 #cybersecurity #infosec

    Post summary

    CISA reports active exploitation of CVE-2024-5274, a critical deserialization flaw in Ray that enables arbitrary code execution; immediate patching or isolation is recommended.

    1001073
    91 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora39--
OSfedoraprojectfedora40--
Appgooglechrome---

Explore more