LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-4671: Google Chromium Visuals Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 13, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 3, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-4671 to its Known Exploited Vulnerabilities catalog on May 13, 2024, with a federal patch deadline of Jun 3, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers…

CVE-2024-4671 is a use-after-free vulnerability in the Visuals component of Google Chromium. A remote attacker can trigger heap corruption by supplying a crafted HTML page, which may allow code execution or other compromise inside the browser process. Because many browsers embed Chromium, the issue can affect Google Chrome, Microsoft Edge, Opera and other Chromium-based products. Organizations that rely on these browsers for everyday web access face elevated risk of drive-by compromise until the flaw is addressed.

CISA has catalogued the vulnerability and directs defenders to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Public detail on exact exploit mechanics remains limited to the high-level description; teams should treat any unpatched Chromium-based browser as potentially exposed.

How it works

The underlying weakness is CWE-416, use-after-free. In a use-after-free condition, memory that has already been freed is later accessed again. When that occurs inside the Visuals rendering path of Chromium, an attacker-controlled HTML page can arrange for the freed region to be reallocated with attacker data. The subsequent use of the stale pointer then corrupts the heap. Heap corruption of this type commonly enables arbitrary code execution within the sandboxed renderer or, in some cases, further privilege escalation. No public exploit code or precise trigger sequence is provided in the available facts; the only confirmed attack vector is a crafted HTML page delivered to a vulnerable browser.

Am I affected? How to find it in your systems

Chromium and Chromium-derived browsers are ubiquitous on endpoints, virtual desktops, kiosks and some server-side rendering services. Inventory every installation of Google Chrome, Microsoft Edge, Opera and any other product that ships a Chromium engine. Check the browser’s “About” dialog or the package version reported by the operating-system package manager; compare those versions against the fixed releases listed in the vendor security advisory. Because the vulnerability resides in the Visuals component, any configuration that enables full HTML rendering is in scope.

Look for signs of exploitation in browser crash dumps, renderer process terminations, and endpoint-detection telemetry that flags heap-corruption or unexpected memory-access violations inside chrome.exe, msedge.exe or equivalent binaries. Web-proxy and DNS logs may also show visits to previously unseen domains that served the malicious HTML. Confirm exact version ranges and detection signatures against the official vendor advisory, as public detail is limited.

How to remediate

The primary remediation is to apply the vendor-supplied update that corrects the use-after-free in the Visuals component. Follow the instructions published by Google for Chromium and by each browser vendor (Microsoft, Opera, etc.) that incorporates the same code base. After patching, verify that the new version is running on all managed endpoints through your software-inventory or configuration-management system.

Additional hardening steps appropriate for this class of browser vulnerability include enabling automatic updates, restricting the ability of standard users to install alternate Chromium forks, and enforcing site-isolation and renderer sandboxing features already present in modern Chromium builds. These measures reduce the blast radius of any residual memory-corruption bugs.

If you can't patch immediately

Until the vendor update can be deployed, apply compensating controls. Segment high-risk user populations onto networks that limit outbound web traffic to known-good destinations. Deploy virtual-patching rules on web application firewalls or secure web gateways that block or sandbox HTML content matching known malicious patterns for this vulnerability class. Where feasible, temporarily disable or restrict the use of Chromium-based browsers for non-essential roles and substitute a fully patched alternative browser. Increase monitoring of renderer crashes and anomalous process creations originating from browser binaries, and alert on any heap-corruption indicators. These steps do not eliminate the vulnerability but reduce the likelihood of successful exploitation until the official fix is installed.

If your data may have been exposed

Actively exploited browser vulnerabilities frequently serve as the initial access vector for broader compromises that can lead to data theft or ransomware. Although ransomware use of CVE-2024-4671 is not documented, any successful heap-corruption attack could allow an adversary to steal session cookies, credentials or files accessible to the browser. Organizations that suspect exposure should review endpoint and network logs for indicators of compromise, rotate credentials that may have been present in the browser, and consider running a free exposure scan of organizational email addresses against known breach data sets to determine whether related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium
WeaknessCWE-416
Added to CISA KEVMay 13, 2024
Federal patch deadlineJun 3, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities