Skip to content
COOEY

EXPOSURES › CVE-2024-4671

CVE-2024-4671

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-4671 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatchedransomware

Google Chromium's use-after-free vulnerability (CVE-2024-4671) allows remote attackers to exploit heap corruption via crafted HTML pages.

This high-severity flaw affects multiple Chromium-based browsers, including Google Chrome, Microsoft Edge, and Opera, enabling remote code execution through unpatched heap corruption. DIB organizations must prioritize patching immediately to prevent ransomware or data exfiltration via compromised browser sessions.

Shame score — While the vulnerability is actively exploited and affects multiple vendors, it is a known issue with a patch available, making it less egregious than negligent vendor behavior.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized