Vulnerability record · CVE-2024-4671 · published 14 May 2024
CVE-2024-4671: Google Chrome Visuals use-after-free enables sandbox escape
Google · Chrome
CVE-2024-4671 is a use-after-free flaw in the Visuals component of Google Chrome prior to 124.0.6367.201. An attacker who has already compromised the renderer process can trigger it with a crafted HTML page to attempt a sandbox escape, which matters because it turns a renderer compromise into a broader host compromise.
Description
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.6 critical severity combined with CISA KEV listing and known exploitation makes this a top remediation priority.
What it is
CVE-2024-4671 is a use-after-free flaw in the Visuals component of Google Chrome prior to 124.0.6367.201. An attacker who has already compromised the renderer process can trigger it with a crafted HTML page to attempt a sandbox escape, which matters because it turns a renderer compromise into a broader host compromise.
Impact
An attacker gains the ability to escape the Chrome sandbox from an already-compromised renderer, potentially reaching the underlying operating system with high confidentiality, integrity and availability impact.
Attack surface
Reached over the network via a crafted HTML page, requiring user interaction to load the page and a pre-existing renderer compromise as a precondition. No privileges are required on the attacker's side per the CVSS vector.
Exploitation
CVE-2024-4671 is listed in CISA KEV with a due date of 2024-06-03, indicating known exploitation; EPSS 30-day probability is about 8.3 percent (94.7th percentile). No ransomware campaign use is documented.
What to do
- Update Google Chrome to 124.0.6367.201 or later, and apply the corresponding Fedora package updates.
- Verify browser version compliance across managed endpoints and block or restrict outdated Chrome builds.
- Enforce site isolation and keep renderer sandboxing enabled to limit the impact of renderer compromise.
- Reduce exposure to untrusted HTML through web filtering and user awareness of malicious pages.
- Track the CISA KEV due date of 2024-06-03 and confirm remediation before it.
Detection
- Monitor for Chrome processes spawning unexpected child processes or making unusual system calls indicative of sandbox escape attempts.
- Alert on renderer crashes or memory corruption events in the Visuals component via crash telemetry.
- Hunt for known exploitation indicators against the Chromium issue 339266700 and vendor advisory references.
- Audit endpoint browser versions to flag hosts still running Chrome below 124.0.6367.201.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-4671 to the Known Exploited Vulnerabilities catalog on 13 May 2024 as "Google Chromium Visuals Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 June 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-4671 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-4671), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.