News Room
16
Share
Google Patches Fourth Chrome Zero-Day in Two Weeks Amid Active Exploitation (CVE-2024-5274)
criticalZero-Day Exploits

Google Patches Fourth Chrome Zero-Day in Two Weeks Amid Active Exploitation (CVE-2024-5274)

Google has issued an emergency patch for CVE-2024-5274, a critical V8 type confusion vulnerability exploited in the wild. This marks the fourth zero-day addressed this month, signaling a surge in browser-targeted attacks.

21 July 2026Last updated 20 August 20265 min readGoogle Threat Analysis Group (TAG)
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2024-5274, CVE-2024-4947, CVE-2024-4671, CVE-2024-4761
Source:
Google Threat Analysis Group (TAG)
Read Time:
5 min

Executive Summary\nOn May 23, 2024, Google released an emergency security update for the Chrome browser to address CVE-2024-5274, a high-severity type confusion vulnerability in the V8 JavaScript engine. Google confirmed that an exploit for this vulnerability exists in the wild, making it the eighth zero-day patched in Chrome in 2024 and the fourth in just a two-week span. The rapid succession of these disclosures suggests a highly volatile threat environment where attackers are aggressively leveraging browser vulnerabilities to gain initial access to target systems.\n\n## Threat Analysis\nCVE-2024-5274 is a type confusion flaw within V8, the open-source JavaScript and WebAssembly engine developed by Google. Type confusion occurs when a program allocates a resource using one functional type but later accesses it using a different, incompatible type. This mismatch allows an attacker to perform out-of-bounds memory access or execution, frequently leading to remote code execution (RCE). In a typical attack scenario, a threat actor tricks a user into visiting a specially crafted malicious website, which then executes the exploit to bypass browser sandboxing and gain control over the underlying operating system.\n\n## Technical Details\nThe vulnerability was reported by Clement Lecigne of Google’s Threat Analysis Group (TAG) and Brendon Tiszka of the Chrome Security team. While specific technical details remain restricted to prevent further exploitation, the involvement of TAG suggests the vulnerability was discovered during investigations into targeted cyber operations. Type confusion in V8 often involves flaws in the JIT (Just-In-Time) compiler or the way the engine optimizes object properties. This particular flaw is suspected to be related to or a bypass of previous mitigations for similar V8 vulnerabilities, such as CVE-2024-4947, which was patched earlier this month.\n\n## Attribution Assessment\nWhile Google has not officially attributed the exploitation of CVE-2024-5274 to a specific threat actor, the profile of the exploit aligns with the tactics of commercial surveillance vendors (CSVs) and advanced persistent threats (APTs). Historically, zero-day vulnerabilities in Chrome are a staple for spyware developers who sell 'one-click' or 'zero-click' exploit chains to nation-state clients for the purpose of high-value espionage. The high frequency of recent Chrome zero-days may indicate that multiple independent actors have discovered similar primitives or that a single highly capable group is burning through their exploit inventory.\n\n## Implications\nThe discovery of four zero-days in Chrome within 15 days (CVE-2024-4671, CVE-2024-4761, CVE-2024-4947, and CVE-2024-5274) creates a significant patch management burden for enterprise security teams. Because Chrome is the foundation for numerous other browsers—including Microsoft Edge, Brave, and Opera—the impact extends far beyond Google’s ecosystem. For organizations, these vulnerabilities represent a critical 'initial access' vector that could precede broader network intrusion, data exfiltration, or the deployment of ransomware.\n\n## Recommendations\nEncrygma strongly recommends that all organizations and individual users immediately update Google Chrome to version 125.0.6422.112/.113 for Windows and macOS, and version 125.0.6422.112 for Linux. Administrators should verify that Chromium-based alternatives, such as Microsoft Edge, have also applied the corresponding upstream fixes. Organizations should consider implementing browser isolation technologies for high-risk users and ensuring that endpoint detection and response (EDR) solutions are configured to monitor for suspicious child processes originating from web browsers.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo