PT-2024-3338 · Google+5 · Google Chrome+5

Published

2024-05-09

·

Updated

2025-07-25

·

CVE-2024-4671

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 124.0.6367.201
Description The issue is a use-after-free vulnerability in the Visuals component of Google Chrome, allowing a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability can cause information disclosure, code execution, or application crash. The estimated number of potentially affected devices is not specified, but it is known that hackers are actively exploiting this vulnerability in the wild.
Recommendations For Google Chrome versions prior to 124.0.6367.201, update to version 124.0.6367.201 or later to patch the vulnerability. As a temporary workaround, consider restricting access to potentially vulnerable API endpoints or disabling the use of the Visuals component until a patch is available. Avoid using Google Chrome until the update is applied, especially when browsing untrusted websites.

Exploit

Fix

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10294
ALT-PU-2024-11865
ALT-PU-2024-14286
ALT-PU-2024-14830
ALT-PU-2024-7693
ALT-PU-2024-9404
ALT-PU-2024-9406
ALT-PU-2024-9716
ALT-PU-2024-9718
BDU:2024-03604
CVE-2024-4671
DSA-5687-1
MGASA-2024-0178
OPENSUSE-SU-2024:0142-1
OPENSUSE-SU-2024:0156-1
OPENSUSE-SU-2024:13953-1
OPENSUSE-SU-2024_0142-1
OPENSUSE-SU-2024_0156-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
Suse