Threat Advisory

Google Chrome Addressing Fifth Zero-Day Exploit in Visuals Component

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A high-severity security update has been released by Google for its Chrome browser, addressing the fifth zero-day vulnerability. Tracked as CVE-2024-4671, the issue involves a "user after free" vulnerability within the Visuals component, responsible for rendering and displaying content on the browser. Such vulnerabilities occur when a program continues to use a pointer after the memory it points to has been freed, potentially leading to data leakage, code execution, or crashes. Google has patched this flaw with the release of Chrome with updates rolling out gradually. This adds to a series of zero-day vulnerabilities discovered in Chrome including CVE-2024-0519, CVE-2024-2887, CVE-2024-2886, and CVE-2024-3159, each posing varying levels of threat ranging from out-of-bounds memory access to type confusion and use-after-free vulnerabilities in critical browser components. Users are advised to ensure their Chrome browser is to mitigate the risk.
[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A high-severity security update has been released by Google for its Chrome browser, addressing the fifth zero-day vulnerability. Tracked as CVE-2024-4671, the issue involves a "user after free" vulnerability within the Visuals component, responsible for rendering and displaying content on the browser. Such vulnerabilities occur when a program continues to use a pointer after the memory it points to has been freed, potentially leading to data leakage, code execution, or crashes. Google has patched this flaw with the release of Chrome with updates rolling out gradually. This adds to a series of zero-day vulnerabilities discovered in Chrome including CVE-2024-0519, CVE-2024-2887, CVE-2024-2886, and CVE-2024-3159, each posing varying levels of threat ranging from out-of-bounds memory access to type confusion and use-after-free vulnerabilities in critical browser components. Users are advised to ensure their Chrome browser is to mitigate the risk.
[emaillocker id="1283"]

RECOMMENDATION:

  • We strongly recommend you update google chrome to version 124.0.6367.201/.202 for Windows, Mac, and version 124.0.6367.201 for Linux.

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/google-fixes-fifth-chrome-zero-day-vulnerability-exploited-in-attacks-in-2024/

[/emaillocker]
crossmenu