CVE-2024-4558 is a critical use-after-free vulnerability in ANGLE within Google Chrome (prior to version 124.0.6367.155), also affecting Apple and Fedora Project products. This flaw allows a remote attacker to potentially achieve heap corruption by enticing a user to visit a crafted HTML page. With a CVSS score of 9.6 (CRITICAL), it presents a high risk of complete compromise (confidentiality, integrity, availability) with low attack complexity and no authentication required. While there is no known active exploitation (KEV list) or public exploit code (Metasploit, Nuclei, ExploitDB), community discussion indicates awareness, and media coverage highlights its inclusion in a broader patch cycle.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 124.0.6367.155CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* | ||
< 17.6CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.