CVE-2024-2886
✓ Confirmed 0-Day
Triaged: March 5, 2026
15 articles
EPSS Score
Source: FIRST.org · 2026-05-24
1.49%
probability
This CVE has a 1.49% probability
of being exploited in the next 30 days.
0%
Top 81.3th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
CWE-118
· Incorrect Access of Indexable Resource ('Range Error')
CWE-119
· Buffer Overflow
CWE-416
· Use After Free
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-666
· Operation on Resource in Wrong Phase of Lifetime
CWE-672
· Operation on a Resource after Expiration or Release
CWE-825
· Expired Pointer Dereference
Google fixes ninth Chrome zero-day tagged as exploited this year
BleepingComputer
Aug 21, 2024
Google tags a tenth Chrome zero-day as exploited this year
BleepingComputer
Aug 26, 2024
Google fixes eighth actively exploited Chrome zero-day this year
BleepingComputer
May 24, 2024
Google fixes third actively exploited Chrome zero-day in a week
BleepingComputer
May 15, 2024
Google fixes fifth Chrome zero-day exploited in attacks this year
BleepingComputer
May 10, 2024
Google Chrome emergency update fixes 6th zero-day exploited in 2024
BleepingComputer
May 14, 2024
Google fixes one more Chrome zero-day exploited at Pwn2Own
BleepingComputer
Apr 03, 2024
Google fixes Chrome zero-days exploited at Pwn2Own 2024
BleepingComputer
Mar 27, 2024
Security Advisory 2024-044
CERT-EU
May 16, 2024
Signal Intelligence
Confidence
85%
EPSS
1.49%
Mentions
15
Last Seen
Aug 26, 2024
CNA Information
Analyst Note
CVE-2024-2886 is explicitly identified as a Chrome zero-day tagged as exploited in the wild by Google in 2024, with multiple authoritative sources (BleepingComputer) confirming active exploitation. The CVE was published March 26, 2024, and patched in Chrome 123.0.6312.86 the same month, consistent with zero-day disclosure and patch timing.
Triage Info
Decided atMar 05, 2026