CVE-2024-4671
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
17 articles
EPSS Score
Source: FIRST.org · 2026-05-24
0.18%
probability
This CVE has a 0.18% probability
of being exploited in the next 30 days.
0%
Top 39.6th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroUse after free in Visuals
Attack Intelligence
CWE-118
· Incorrect Access of Indexable Resource ('Range Error')
CWE-119
· Buffer Overflow
CWE-416
· Use After Free
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-666
· Operation on Resource in Wrong Phase of Lifetime
CWE-672
· Operation on a Resource after Expiration or Release
CWE-825
· Expired Pointer Dereference
Google Project Zero
Discovered
May 7, 2024
Patched
May 9, 2024
Reported by
???
Root Cause Analysis
???
Google fixes ninth Chrome zero-day tagged as exploited this year
BleepingComputer
Aug 21, 2024
Google tags a tenth Chrome zero-day as exploited this year
BleepingComputer
Aug 26, 2024
Google fixes eighth actively exploited Chrome zero-day this year
BleepingComputer
May 24, 2024
Google fixes third actively exploited Chrome zero-day in a week
BleepingComputer
May 15, 2024
Google fixes fifth Chrome zero-day exploited in attacks this year
BleepingComputer
May 10, 2024
Get Weekends Back: Put Chrome CVEs like CVE-2024-5274 on Auto-Patching
Qualys
May 11, 2024
Google Chrome emergency update fixes 6th zero-day exploited in 2024
BleepingComputer
May 14, 2024
Security Advisory 2024-044
CERT-EU
May 16, 2024
Russian APT29 hackers use iOS, Chrome exploits created by spyware vendors
BleepingComputer
Aug 29, 2024
Signal Intelligence
Confidence
92%
EPSS
0.18%
Mentions
17
Last Seen
Aug 29, 2024
CNA Information
Analyst Note
CVE-2024-4671 is confirmed as actively exploited in the wild, with multiple credible sources (BleepingComputer) documenting Google's acknowledgment of this zero-day exploitation. The critical CVSS score (9.6) combined with sandbox escape capability and documented active exploitation in 2024 provides strong corroboration for the confirmed status.
Threat Actors 5
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Pat Bear
apt_group
🇸🇾 SY
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 03, 2026