Junglewise Threat Intelligence

CVE-2024-4671: Google Chromium Visuals Use-After-Free Vulnerability

CVE-2024-4671 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2024-05-13

Technologies: Google Chromium, Microsoft Edge, Google Chrome. Vendors: Opera, Google, Microsoft.

Executive brief

A use-after-free vulnerability in the Visuals component of Google Chromium allows a remote attacker to exploit heap corruption via a crafted HTML page. If the renderer process is compromised, this flaw can potentially lead to a sandbox escape.

Affected products

  • Google Chrome prior to 124.0.6367.201
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2024-05-09: patched: Stable channel update for desktop released.
  • 2024-05-13: disclosed: CVE published and added to CISA KEV catalog.
  • 2024-05-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
  • 2024-05-13: exploited: Reported as exploited in the wild.

Related threats