CVE-2024-4947

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 13 articles

EPSS Score

Source: FIRST.org · 2026-05-24
0.97%
probability
This CVE has a 0.97% probability of being exploited in the next 30 days.
0% Top 76.8th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Type Confusion in V8

Attack Intelligence

Google Project Zero

Discovered
May 13, 2024
Patched
May 15, 2024
Reported by
Vasily Berdnikov (@vaber_b) and Boris Larin (@oct0xor) of Kaspersky
Root Cause Analysis
???

Signal Intelligence

Confidence
92%
EPSS 0.97%
Mentions 13
Last Seen Oct 23, 2024

CNA Information

Analyst Note

CVE-2024-4947 is a confirmed zero-day with strong evidence of active exploitation, including attribution to Lazarus hackers using a fake DeFi game attack vector. The critical CVSS 9.6 score, presence in Google Project Zero, multiple independent security news sources documenting active exploits, and timely patching in Chrome 125.0.6422.60 all support the confirmed status.

Threat Actors 23

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
APT27
apt_group Information theft and espionage 🇨🇳 CN
Cobalt
apt_group Financial crime 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
GhostEmperor
apt_group Information theft and espionage 🇨🇳 CN
APT3
apt_group Information theft and espionage 🇨🇳 CN
Infy
apt_group Information theft and espionage 🇮🇷 IR
Volt Typhoon
apt_group Information theft and espionage 🇨🇳 CN
Callisto Group
apt_group Information theft and espionage 🇷🇺 RU
Callisto
apt_group Information theft and espionage 🇷🇺 RU
FamousSparrow
apt_group Information theft and espionage 🇨🇳 CN
APT31
apt_group Information theft and espionage 🇨🇳 CN
Flax Typhoon
apt_group Information theft and espionage 🇨🇳 CN
UAC-0063
apt_group 🇷🇺 RU
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Shadow Academy
apt_group Information theft and espionage 🇮🇷 IR
Pat Bear
apt_group 🇸🇾 SY
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Impersonating Panda
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 03, 2026