Google released a security update for CVE-2024-4671, a high-severity use-after-free vulnerability in Chrome’s Visuals component, and confirmed that an exploit exists in the wild. The flaw could allow remote code execution. An anonymous researcher reported it on May 7, 2024, and Google announced the fix on May 9; the desktop update contained one security fix.
The patched Stable releases are 124.0.6367.201/.202 for Windows and macOS and 124.0.6367.201 for Linux. Extended Stable was updated to 124.0.6367.201 for Windows and macOS, with rollout scheduled over the following days and weeks. Organizations should verify that managed browsers have received the fix or a newer release and prioritize unpatched endpoints because exploitation has been observed.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
An anonymous researcher reported CVE-2024-4671 to Google on May 7, 2024. The high-severity use-after-free vulnerability affects Chrome's Visuals component.
Google released a security update for CVE-2024-4671 and stated that an exploit exists in the wild. Fixed versions are 124.0.6367.201/.202 for Stable on Windows and Mac, 124.0.6367.201 for Stable on Linux, and 124.0.6367.201 for Extended Stable on Windows and Mac.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.