CRITICAL
CVE-2024-4671
CVSS
9.6
KEV
Description
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
A use-after-free vulnerability exists in the Visuals component of Google Chrome versions prior to 124.0.6367.201. This memory corruption flaw allows a remote attacker who has already compromised the renderer process to potentially escape Chrome's sandbox security boundary by exploiting the freed memory through a specially crafted HTML page.
Mitigation
Update Google Chrome to version 124.0.6367.201 or later to patch this vulnerability. Organizations should ensure browser update policies are enforced across their fleet.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
8.35%
Probability of exploitation in next 30 days
94.8th percentile
References
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html
Vendor Advisory
https://issues.chromium.org/issues/339266700
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BWFSZNNWSQYDRYKNLBDGEXXKMBXDYQ3F/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FAWEKDQTHPN7NFEMLIWP7YMIZ2DHF36N/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NTSN22LNYXMWHVTYNOYQVOY7VDZFHENQ/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WSUWM73ZCXTN62AT2REYQDD5ZKPFMDZD/
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4671
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.