CVE-2024-21640(chromiumembedded / chromium_embedded_framework)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read out of the sandbox. This vulnerability was patched in commit 1f55d2e.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chromium_embedded_framework

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Products
chromium_embedded_framework

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-22: 109-22
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc

    ShinyHunters exploited CVE-2024-21640 in Clop's dark web leak site, escalating from CMS access to steal victim payment records and operational data. The attackers now threaten to re-extort companies that previously paid Clop ransoms. Runtime segmentation of management infrastructure helps limit such lateral movement scenarios. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/shinyhunters-hacked-clop-ransomware-victims-2026

    0000060
    2.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchromiumembeddedchromium_embedded_framework---

Explore more