CVE-2024-4671

9.6CRITICAL

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (

Veröffentlicht: 5/14/2024Aktualisiert: 10/24/2025

CISA Bekannte Ausgenutzte Schwachstelle

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Erforderliche Maßnahme:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Fälligkeitsdatum:

2024-06-03

Beschreibung

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

KI-AnalyseKI-gestützt

Betroffene Produkte

googlechrome
fedoraprojectfedora
38
fedoraprojectfedora
39
fedoraprojectfedora
40

Referenzen