CVE-2023-0474Use After Free in Google Chrome

CWE-416Use After Free8 documents7 sources
Severity
8.8HIGHNVD
EPSS
0.1%
top 67.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateFeb 21

Description

Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a Chrome web app. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

CVEListV5google/chromeunspecified109.0.5414.119
NVDgoogle/chrome< 109.0.5414.119
debiandebian/chromium< chromium 109.0.5414.119-1 (bookworm)
Debianchromium/chromium< 109.0.5414.119-1~deb11u1+3

🔴Vulnerability Details

3
OSV
chromium-browser vulnerabilities2023-02-21
OSV
CVE-2023-0474: Use after free in GuestView in Google Chrome prior to 1092023-01-30
GHSA
GHSA-wj5q-gv6p-4mq7: Use after free in GuestView in Google Chrome prior to 1092023-01-30

📋Vendor Advisories

4
Ubuntu
Chromium vulnerabilities2023-02-21
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-04742023-01-31
Microsoft
Chromium: CVE-2023-0474 Use after free in GuestView2023-01-10
Debian
CVE-2023-0474: chromium - Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an ...2023