Header image

Google Fixes Chrome Zero Day Vulnerability

Vulnerability would allow a remote attacker to perform a sandbox escape via a crafted HTML page.


Google has said that it is aware that an exploit for CVE-2024-4671 exists in the wild, and issued a fix for the zero-day vulnerability.

The vulnerability, rated as high, impacts Google Chrome for Windows, Mac, and Linux and relates to a use after free condition in Visuals.

An advisory from MITRE explained that exploiting the vulnerability would allow a remote attacker - who had compromised the renderer process - to potentially perform a sandbox escape via a crafted HTML page.

This is the fifth zero-day fix of 2024 by Google Chrome, with two fixes coming in March.

Dan Raywood
Dan Raywood

Dan Raywood is a B2B journalist with 25 years of experience, including covering cybersecurity for the past 17 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Forum, BSides Scotland, Steelcon and the National Cyber Security Show, and served as editor of SC Media UK, Infosecurity Magazine and IT Security Guru. He was also an analyst with 451 Research and a product marketing lead at Tenable.

Dan Raywood
Dan Raywood

Dan Raywood is a B2B journalist with 25 years of experience, including covering cybersecurity for the past 17 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Forum, BSides Scotland, Steelcon and the National Cyber Security Show, and served as editor of SC Media UK, Infosecurity Magazine and IT Security Guru. He was also an analyst with 451 Research and a product marketing lead at Tenable.

Upcoming Events

No events found.