CVE-2024-4671Active Exploitation(fedoraproject / chrome)

MEDIUMCVSS 9.6 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fedoraproject chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-06-03. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • fedora

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Peaked 1d ago at 1 mentions (2026-03-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
chromefedora

3 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-23: 1Mentions · 2026-06-09: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-06-09: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-06-09: 103-2306-09
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • nksistemas@nksistemas
    Active Exploitation

    Alerta Crítica: Chrome 0-Day (CVE-2024-4671) Explotado Activamente – ¡Actualiza Ya! https://nksistemas.com/alerta-critica-chrome-0-day-cve-2024-4671-explotado-activamente-actualiza-ya/

    Post summary

    A warning alerts that Chrome CVE‑2024‑4671 is actively exploited, urging users to update immediately.

    0101056
    6.2K followersView on X
  • Cyber Netsec IO@NetSecIO
    Active Exploitation

    📢 CISA KEV UPDATE: Actively exploited flaws in Apple visionOS (CVE-2026-28217), Laravel (CVE-2024-4671), & Craft CMS (CVE-2026-25487) added to catalog. Federal agencies must patch by April 12. All orgs urged to patch NOW! ⚠️ #KEV #CISA 🔗 https://cyber.netsecops.io/articles/cisa-adds-apple-laravel-craft-cms-flaws-to-kev-catalog/?utm_source=twitter&utm_medium=social&utm_campaign=twitter_auto

    Post summary

    The update alerts that CVEs affecting Apple visionOS, Laravel, and Craft CMS are actively exploited and urges organizations to patch immediately.

    0000055
    34 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora38--
OSfedoraprojectfedora39--
OSfedoraprojectfedora40--
Appgooglechrome---

Explore more