CRITICAL

CVE-2024-4671

Google Chrome 2024-05-14 CVSS v3.1
CVSS
9.6
KEV

Description

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

A use-after-free vulnerability exists in the Visuals component of Google Chrome versions prior to 124.0.6367.201. This memory corruption flaw allows a remote attacker who has already compromised the renderer process to potentially escape Chrome's sandbox security boundary by exploiting the freed memory through a specially crafted HTML page.

Mitigation

Update Google Chrome to version 124.0.6367.201 or later to patch this vulnerability. Organizations should ensure browser update policies are enforced across their fleet.

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

8.35%
Probability of exploitation in next 30 days
94.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE