Executive brief
A use-after-free vulnerability in the Visuals component of Google Chromium allows a remote attacker to exploit heap corruption via a crafted HTML page. If the renderer process is compromised, this flaw can potentially lead to a sandbox escape.
Affected products
- Google Chrome prior to 124.0.6367.201
- Microsoft Edge
- Opera Opera
Timeline
- 2024-05-09: patched: Stable channel update for desktop released.
- 2024-05-13: disclosed: CVE published and added to CISA KEV catalog.
- 2024-05-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- 2024-05-13: exploited: Reported as exploited in the wild.