Sandbox Escape Vulnerability in Visuals in Google Chrome
Key Information
- Vendor
- Status
- Chrome
- Vendor
- CVE Published:
- 14 May 2024
Badges
Summary
The vulnerability is a high-severity "use-after-free" bug in the Visuals component of Google Chrome, known as CVE-2024-4671. Although there is confirmation that an exploit exists, there have been no instances of active exploitation at this time. The flaw poses a risk to users of all operating systems, including Mac, Windows, and Linux. The exploitation of the vulnerability can result in the reading of data from the user's computer, crashes, and potential takeover of the system. It is recommended that users update their Chrome browsers immediately to the latest version to protect against this vulnerability.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-4671 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
Chrome < 124.0.6367.201
News Articles
Russian Hackers Exploit Safari and Chrome Flaws in High-Profile Cyberattack
Russian hackers exploit patched Safari and Chrome flaws in attacks on Mongolian government websites, targeting mobile users.
3 months ago
Chrome浏览器存在远程代码执行漏洞(CVE-2024-4671)
Chrome浏览器UAF漏洞 (CVE-2024-4671) Google Chrome是一款广泛使用的跨平台Web浏览器,由Google开发。它基于Chromium开源项目,提供快速、安全和用户友好的浏览体验。Chrome浏览器在全球拥有大量用户,是最受欢迎的Web浏览器之一。 01 漏洞描述 漏洞类型:Chrome浏览器UAF漏洞...
3 months ago
Google discloses 2 zero-day vulnerabilities in less than a week | T...
Google said two zero-day vulnerabilities, tracked as CVE-2024-4761 and CVE-2024-4671, have exploits available in the wild.
6 months ago
CVSS V3.1
Timeline
- 👾
Exploit exists.
Vulnerability published.
Vulnerability started trending.
First article discovered by SecurityWeek
Vulnerability Reserved.