CVE-2024-4671

CRITICAL KEV

Google Chrome < 124.0.6367.201 - Use-After-Free in Visuals

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-4671 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 13, 2024.

Description

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Scores

CVSS v3 9.6
EPSS 0.0057
EPSS Percentile 69.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2024-05-13
VulnCheck KEV 2024-05-07
InTheWild.io 2024-05-07
ENISA EUVD EUVD-2024-44272
CWE
CWE-416
Status published
Products (4)
fedoraproject/fedora 38
fedoraproject/fedora 39
fedoraproject/fedora 40
google/chrome < 124.0.6367.201
Published May 14, 2024
KEV Added May 13, 2024
Tracked Since Feb 18, 2026