CVE-2023-0699
published 2023-02-07CVE-2023-0699: Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.77%
52.0th percentile
Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 110.0.5481.77-1~deb11u1 | 110.0.5481.77-1~deb11u1 |
| chromium | chromium | >= 0 < 110.0.5481.77-1 | 110.0.5481.77-1 |
| chromium | chromium | >= 0 < 110.0.5481.77-1 | 110.0.5481.77-1 |
| chromium | chromium | >= 0 < 110.0.5481.77-1 | 110.0.5481.77-1 |
| debian | chromium | < chromium 110.0.5481.77-1 (bookworm) | chromium 110.0.5481.77-1 (bookworm) |
| chrome | < 110.0.5481.77 | 110.0.5481.77 | |
| chrome | >= unspecified < 110.0.5481.77 | 110.0.5481.77 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Chromium vulnerabilities
vendor_ubuntu·2023-02-21·CVSS 8.8
CVE-2023-0700 [HIGH] Chromium vulnerabilities
Title: Chromium vulnerabilities
Summary: Several security issues were fixed in Chromium.
It was discovered that Chromium did not properly manage memory. A remote
attacker could possibly use these issues to cause a denial of service or
execute arbitrary code via a crafted HTML page. (CVE-2023-0471,
CVE-2023-0472, CVE-2023-0473, CVE-2023-0696, CVE-2023-0698, CVE-2023-0699,
CVE-2023-0702, CVE-2023-0705)
It was discovered that Chromium did not properly manage memory. A remote
attacker who convinced a user to install a malicious extension could
possibly use this issue to corrupt memory via a Chrome web app.
(CVE-2023-0474)
It was discovered that Chromium contained an inappropriate implementation
in the Download component. A remote attacker could possibly use this issue
to spoof contents of
Microsoft
Chromium: CVE-2023-0699 Use after free in GPU
vendor_msrc·2023-02-14·CVSS 8.8
CVE-2023-0699 [HIGH] Chromium: CVE-2023-0699 Use after free in GPU
Chromium: CVE-2023-0699 Use after free in GPU
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
FAQ: What is
Chrome
Stable Channel Update for Desktop: CVE-2023-0699
vendor_chrome·2023-02-07·CVSS 8.8
CVE-2023-0699 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-0699
Stable Channel Update for Desktop
CVE-2023-0699: Use after free in GPU. Reported by 7o8v and Cassidy Kim(@cassidy6564) on 2022-10-06 [$3000][ 1393732 ] Medium CVE-2023-0700: Inappropriate implementation in Download
Reported by Axel Chong on 2022-11-26 [$2000][ 1405123 ] Medium CVE-2023-0701: Heap buffer overflow in WebUI
Severity: medium
Debian
CVE-2023-0699: chromium - Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote a...
vendor_debian·2023·CVSS 8.8
CVE-2023-0699 [HIGH] CVE-2023-0699: chromium - Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote a...
Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 110.0.5481.77-1)
bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1)
forky: resolved (fixed in 110.0.5481.77-1)
sid: resolved (fixed in 110.0.5481.77-1)
trixie: resolved (fixed in 110.0.5481.77-1)
OSV
chromium-browser vulnerabilities
osv·2023-02-21·CVSS 8.8
CVE-2023-0471 [HIGH] chromium-browser vulnerabilities
chromium-browser vulnerabilities
It was discovered that Chromium did not properly manage memory. A remote
attacker could possibly use these issues to cause a denial of service or
execute arbitrary code via a crafted HTML page. (CVE-2023-0471,
CVE-2023-0472, CVE-2023-0473, CVE-2023-0696, CVE-2023-0698, CVE-2023-0699,
CVE-2023-0702, CVE-2023-0705)
It was discovered that Chromium did not properly manage memory. A remote
attacker who convinced a user to install a malicious extension could
possibly use this issue to corrupt memory via a Chrome web app.
(CVE-2023-0474)
It was discovered that Chromium contained an inappropriate implementation
in the Download component. A remote attacker could possibly use this issue
to spoof contents of the Omnibox (URL bar) via a crafted HTML page.
(CVE-2023-
GHSA
GHSA-7qjc-w955-mq5c: Use after free in GPU in Google Chrome prior to 110
ghsa_unreviewed·2023-02-07
CVE-2023-0699 [HIGH] CWE-416 GHSA-7qjc-w955-mq5c: Use after free in GPU in Google Chrome prior to 110
Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)
OSV
CVE-2023-0699: Use after free in GPU in Google Chrome prior to 110
osv·2023-02-07·CVSS 8.8
CVE-2023-0699 [HIGH] CVE-2023-0699: Use after free in GPU in Google Chrome prior to 110
Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
Qualys
2023 Threat Landscape Year in Review: If Everything Is Critical, Nothing Is
blogs_qualys·2023-12-19
2023 Threat Landscape Year in Review: If Everything Is Critical, Nothing Is
## Table of Contents
2023 Statistics
2023 Vulnerability Threat Landscape
Top Vulnerability Types
Key Insights
Top MITRE ATT&CK Tactics & Techniques
Most Active Threats
Conclusion
As 2023 nears its end, it’s time to pause and reflect. It’s time to assess what worked and what didn’t, what caught our attention and caused disruption, and what went unnoticed. More importantly, we need to know what lessons we learned from 2023 so that we can do a better job of managing risk in the coming year. In line with this, the Qualys Threat Research Unit has prepared a comprehensive blog series to review the threat landscape in 2023.
Key Takeaways:
Less than one percent of vulnerabilities contributed to the highest risk and were routinely exploited in the wild.
97 high-risk vulnerabilities, like
Qualys
Top Cyber Threats of 2023: An In-Depth Review (Part One) | Qualys
blogs_qualys·2023-12-19
Top Cyber Threats of 2023: An In-Depth Review (Part One) | Qualys
#### Table of Contents
- 2023 Statistics
- 2023 Vulnerability Threat Landscape
- Top Vulnerability Types
- Key Insights
- Top MITRE ATT&CK Tactics & Techniques
- Most Active Threats
- Conclusion
As 2023 nears its end, it’s time to pause and reflect. It’s time to assess what worked and what didn’t, what caught our attention and caused disruption, and what went unnoticed. More importantly, we need to know what lessons we learned from 2023 so that we can do a better job of managing risk in the coming year. In line with this, the Qualys Threat Research Unit has prepared a comprehensive blog series to review the threat landscape in 2023.
Key Takeaways:
- Less than one percent of vulnerabilities contributed to the highest risk and were routinely exploited in the wild.
- 97 high-risk vulnerab
https://chromereleases.googleblog.com/2023/02/stable-channel-update-for-desktop.htmlhttps://crbug.com/1371859https://security.gentoo.org/glsa/202309-17https://chromereleases.googleblog.com/2023/02/stable-channel-update-for-desktop.htmlhttps://crbug.com/1371859https://security.gentoo.org/glsa/202309-17
2023-02-07
Published