Threat Research Knowledge Base Vulnerabilities CVE-2024-4558
CVE-2024-4558
Description
CVE-2024-4558 is a use-after-free vulnerability in the ANGLE component of Google Chrome. Processing maliciously crafted web content may lead to an unexpected process crash.
Impact
Exploitation of this vulnerability could allow attackers to execute arbitrary code on the affected devices, leading to potential data breaches, unauthorized access, or further compromise of the system.The severity of this issue has been assessed as follows:
NIST assessment
CVSS v3.1 Base Score: 9.6 (Critical)
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA-ADP assessment
CVSS v3.1 Base Score: 7.5 (High)
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Has been exploited in the wild
No
Operating systems impacted
- macOS Sonoma (prior to 14.6)
- iOS (prior to 17.6)
- iPadOS (prior to 17.6)
Additional resources
Apps impacted
- Safari (prior to 17.6)
- Google Chrome (prior to 124.0.6367.155)
Related
Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized elevation of privileges by a malicious application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized access to sensitive location information by an application. The severity of this issue has been assessed as follows:
Manage and secure your Apple devices at scale.
