{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-4671",
  "revision": 1,
  "title": "Google Chrome — freed memory in the Visuals component",
  "summary": "A crafted page reaches memory Chrome has already released in its Visuals component. An attacker who already controls the rendering process chains it to break out of the browser's isolation. Fixed in 124.0.6367.201.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.6,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.08348,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2024-05-13",
    "prerequisites": "The attacker must already have compromised the browser's rendering process."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "Google Chrome >= 124.0.6367.201"
    ]
  },
  "mitre_attack": [
    "T1203"
  ],
  "kill_chain": "execution",
  "recommended_action": "Update Chrome to 124.0.6367.201 or later and treat the other Chromium browsers the same. This is the second half of a chain, so a partial rollout leaves the pair usable.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-4671",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-4671",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-4671",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4671",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html"
    }
  ],
  "published_at": "2024-05-14T15:44:15.573Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "google",
    "chrome",
    "chromium",
    "use-after-free",
    "browser",
    "kev"
  ]
}
