Multiple Vulnerabilities in Google Chrome and Microsoft Edge
Multiple vulnerabilities in Google Chrome and Microsoft Edge allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass sandbox protections, and perform information disclosure.
CVE search metadata
CVE search record: CVE-2024-4671. Severity: critical. CVSS: 9.6. EPSS: 8.35%. KEV: no. Product: Chrome, Edge. Brief: Multiple Vulnerabilities in Google Chrome and Microsoft Edge. Brief link: https://feed.craftedsignal.io/briefs/2026-08-chrome-edge-vulnerabilities/
What's new
- 1. added CVE-2024-4671 Aug 27, 11:33 via bsi
Multiple vulnerabilities have been identified in the Google Chrome and Microsoft Edge web browsers, both of which are based on the Chromium engine. These flaws allow a remote, unauthenticated attacker to exploit browser-based weaknesses to achieve arbitrary code execution, escape the browser's sandbox environment, and disclose sensitive information. While specific vulnerability identifiers were not detailed in the source advisory, these flaws represent a significant threat to browser security. Defenders should treat these as high-priority updates for all enterprise endpoints, as browser-based exploitation is a common vector for initial access and payload delivery.
Impact
Successful exploitation of these vulnerabilities compromises the confidentiality, integrity, and availability of the browser session and potentially the underlying host system. In scenarios where sandbox escapes are achieved, an attacker can transition from browser-level control to host-level command execution, increasing the risk of full system compromise, data theft, and persistent malware installation.
Recommendation
Prioritize the deployment of vendor-provided security updates for all versions of Google Chrome and Microsoft Edge within the environment. Ensure that auto-update mechanisms are functioning correctly across all managed endpoints to mitigate the risk of exploitation.
Mitigations
Deploy browser updates to latest versions for Chrome and Edge
Multiple browser vulnerabilities