CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2024-4671

CVSS 9.6v3.1pub. 2024-05-14upd. 2025-10-24

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🤖 AI Analysis
How it works

The use-after-free error consists of accessing a memory area after it has been freed, leading to uncontrolled program behavior. In this case, the vulnerability occurs in the Visuals subsystem responsible for graphics rendering in Chrome. An attacker who has previously compromised the renderer process can provide a specially crafted HTML page that triggers this error and enables code execution outside the isolated browser sandbox environment.

Impact

An attacker can escape the browser sandbox and potentially gain the ability to execute code in the operating system context, which may lead to complete takeover of the victim's system, data theft, and violation of system integrity and availability.

Mitigation & patch

Google Chrome must be updated immediately to version 124.0.6367.201 or later. Users of Fedora distributions should apply package updates according to announcements available in Fedora package-announce mailing lists. It is recommended to enable automatic browser updates.

Who is affected

Google Chrome in versions earlier than 124.0.6367.201 and related Fedora Linux packages (Fedoraproject Fedora)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Fedora Project Fedora

    OS
    Fedoraproject
    383940
  • Google Chrome

    APP
    Google
    < 124.0.6367.201

CISA KEV — detailsi

Vendori
Google
Producti
Chromium
Added to KEVi
May 13, 2024
Remediation deadline (US Federal)i
June 3, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 3 czerwca 2024
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2024-7971CRITICAL9.6⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit

CVE-2024-5274CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML

CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)