Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch fedoraproject chrome systems immediately
Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-06-03. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
📢 CISA KEV UPDATE: Actively exploited flaws in Apple visionOS (CVE-2026-28217), Laravel (CVE-2024-4671), & Craft CMS (CVE-2026-25487) added to catalog. Federal agencies must patch by April 12. All orgs urged to patch NOW! ⚠️ #KEV#CISA
🔗 https://cyber.netsecops.io/articles/cisa-adds-apple-laravel-craft-cms-flaws-to-kev-catalog/?utm_source=twitter&utm_medium=social&utm_campaign=twitter_auto
Post summary
The update alerts that CVEs affecting Apple visionOS, Laravel, and Craft CMS are actively exploited and urges organizations to patch immediately.