CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-4671

Critical Severity|Google
82
SVRS
9.6
CVSSv3
0.00566
EPSS
TAGS
In The WildExploit AvaliableCISA KEV
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:RS:CC:HI:HA:H
PUBLICATION DATE2024-05-09
LAST MODIFIED2025-10-21

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-4671, is a Use-After-Free (UAF) flaw located in the Visuals component of Google Chrome. A Use-After-Free vulnerability occurs when a program tries to use memory that has already been freed, which can lead to unpredictable behavior, including crashes, corruption of data, or arbitrary code execution. This particular vulnerability allows a remote attacker, who has already compromised the renderer process, to potentially perform a sandbox escape via a specially crafted HTML page. This is critical because a sandbox escape bypasses one of Chrome's fundamental security mechanisms, allowing an attacker to break out of the isolated browser environment and gain access to the underlying operating system and its resources, potentially leading to full system compromise.
2. What are the CVSS score, severity level, and disclosure details?
The Common Vulnerability Scoring System (CVSS) score for CVE-2024-4671 is 9.6. This CVSS score indicates a Critical severity level. The vulnerability was publicly published on 2024-05-09 23:54:09 and was last modified on 2025-10-21 23:05:18. The Chromium security severity is rated as High.
3. Which products, vendors, systems, and versions are affected?
The affected product is Google Chrome, developed by Google. Specifically, all versions of Google Chrome prior to 124.0.6367.201 are vulnerable.
4. What is the technical root cause and attack vector?
The technical root cause of this vulnerability is a Use-After-Free (UAF) error (CWE-416) within the Visuals component of Google Chrome. The attack vector involves a remote attacker who has already successfully compromised the browser's renderer process. Once the renderer process is compromised, the attacker can then craft and deliver a malicious HTML page. This crafted HTML page is designed to trigger the UAF condition in the Visuals component, leading to the subsequent sandbox escape.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by a remote attacker in a multi-stage attack. First, the attacker must compromise the Google Chrome renderer process, likely through another vulnerability (e.g., a remote code execution flaw in the renderer). Once the renderer is compromised, the attacker can then serve a specially crafted HTML page to the victim. This crafted HTML page interacts with the Visuals component in a way that triggers the Use-After-Free condition. Successful exploitation leads to a sandbox escape, allowing the attacker to execute arbitrary code outside the browser's security sandbox, gaining elevated privileges and potentially control over the underlying operating system. The presence of published active exploits increases the immediate threat.
6. What mitigation steps and patches are available?
The primary mitigation step and patch available for this vulnerability is to update Google Chrome to a secure version. Users and administrators should ensure that Google Chrome is updated to version 124.0.6367.201 or later. Timely application of this update will remediate the Use-After-Free vulnerability in the Visuals component.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by checking the installed version of Google Chrome. Any instance of Google Chrome running a version prior to 124.0.6367.201 is considered vulnerable to CVE-2024-4671. Users can typically check their Chrome version by navigating to "Help > About Google Chrome" in the browser's menu.
8. What are the indicators of compromise (IOCs)?
9. Which threat actors are known to exploit this vulnerability?
10. What public intelligence references and advisories exist?
The primary public intelligence reference for this vulnerability is its CVE identifier, CVE-2024-4671. Given the Chromium security severity rating of "High," Google would have issued official security advisories or release notes detailing the fix in Chrome version 124.0.6367.201. These advisories serve as official intelligence references.
11. What is the risk assessment and urgency level?
The risk assessment for CVE-2024-4671 is High, and the urgency level is Critical. This assessment is based on several factors:
  • CVSS Score: A score of 9.6 out of 10 signifies critical severity.
  • Impact: The vulnerability allows for a sandbox escape, which is a severe security bypass. This could lead to an attacker executing code outside the browser's security boundaries, potentially leading to full system compromise.
  • Exploitability: The vulnerability is exploitable by a remote attacker with a crafted HTML page, assuming initial renderer compromise. Furthermore, the information states that active exploits have been published, indicating that the vulnerability is actively being targeted or proof-of-concept code is publicly available, increasing the immediate threat.
Organizations and individual users should prioritize updating affected systems immediately to mitigate the significant risk posed by this vulnerability.

No IOCs found for this CVE

TitleSoftware LinkDate
Google Chromium Visuals Use-After-Free Vulnerabilityhttps://www.cisa.gov/search?g=CVE-2024-46712024-05-13
SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

avatar
Cyber Netsec IO@NetSecIO
2026-03-23
📢 CISA KEV UPDATE: Actively exploited flaws in Apple visionOS (CVE-2026-28217), Laravel (CVE-2024-4671), & Craft CMS (CVE-2026-25487) added to catalog. Federal agencies must patch by April 12. All orgs urged to patch NOW! ⚠️ #KEV #CISA 🔗 https://t.co/POPJ8rW5Pf
avatar
Ferramentas Linux@Cezar_H_Linux
2025-07-25
Headline: 🚨 URGENT: Critical #Chromium Vuln Patched in #Debian (DSA-5963-1). CVE-2024-4671 = RCE + Sandbox Escape Risk! Body: High-severity flaw in Chromium engine patched by Debian. Read more: 👉 https://t.co/ny63bU9g23 https://t.co/EFrDpRErNN
avatar
Rony@CyberRonyGlobal
2025-07-01
Hackers are exploiting recent Chrome vulnerabilities (e.g. CVE-2024-4671) to execute remote code & steal data via malicious web pages ✅ Avoid sketchy websites & extensions ✅ Enable site isolation in settings A single tab can be a trap #Chrome #CyberSecurity #BrowserSecurity
Configuration 1
TypeVendorProduct
AppGooglechrome
Configuration 2
TypeVendorProduct
OSFedoraprojectfedora
ReferenceLink
AF854A3A-2127-422B-91AE-364DA2661108https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/BWFSZNNWSQYDRYKNLBDGEXXKMBXDYQ3F/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/FAWEKDQTHPN7NFEMLIWP7YMIZ2DHF36N/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/NTSN22LNYXMWHVTYNOYQVOY7VDZFHENQ/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/WSUWM73ZCXTN62AT2REYQDD5ZKPFMDZD/
[email protected]https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html
[email protected]https://issues.chromium.org/issues/339266700
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/BWFSZNNWSQYDRYKNLBDGEXXKMBXDYQ3F/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/FAWEKDQTHPN7NFEMLIWP7YMIZ2DHF36N/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/NTSN22LNYXMWHVTYNOYQVOY7VDZFHENQ/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/WSUWM73ZCXTN62AT2REYQDD5ZKPFMDZD/
AF854A3A-2127-422B-91AE-364DA2661108https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html
AF854A3A-2127-422B-91AE-364DA2661108https://issues.chromium.org/issues/339266700
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/BWFSZNNWSQYDRYKNLBDGEXXKMBXDYQ3F/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/FAWEKDQTHPN7NFEMLIWP7YMIZ2DHF36N/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/NTSN22LNYXMWHVTYNOYQVOY7VDZFHENQ/
AF854A3A-2127-422B-91AE-364DA2661108https://lists.fedoraproject.org/archives/list/[email protected]/message/WSUWM73ZCXTN62AT2REYQDD5ZKPFMDZD/
[email protected]https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html
[email protected]https://issues.chromium.org/issues/339266700
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/BWFSZNNWSQYDRYKNLBDGEXXKMBXDYQ3F/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/FAWEKDQTHPN7NFEMLIWP7YMIZ2DHF36N/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/NTSN22LNYXMWHVTYNOYQVOY7VDZFHENQ/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/WSUWM73ZCXTN62AT2REYQDD5ZKPFMDZD/
[email protected]https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html
[email protected]https://issues.chromium.org/issues/339266700
[email protected]https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html
[email protected]https://issues.chromium.org/issues/339266700
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/BWFSZNNWSQYDRYKNLBDGEXXKMBXDYQ3F/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/FAWEKDQTHPN7NFEMLIWP7YMIZ2DHF36N/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/NTSN22LNYXMWHVTYNOYQVOY7VDZFHENQ/
[email protected]https://lists.fedoraproject.org/archives/list/[email protected]/message/WSUWM73ZCXTN62AT2REYQDD5ZKPFMDZD/
CWE IDCWE NameDescription
CWE-416Use After FreeReferencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.