CVE-2023-2134Out-of-bounds Write in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.7%
top 28.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateMay 12

Description

Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5google/chrome112.0.5615.137112.0.5615.137
NVDgoogle/chrome< 112.0.5615.137
debiandebian/chromium< chromium 112.0.5615.138-1 (bookworm)
Debianchromium/chromium< 112.0.5615.138-1~deb11u1+3

Also affects: Debian Linux 11.0, Fedora 36, 37, 38

🔴Vulnerability Details

2
OSV
CVE-2023-2134: Out of bounds memory access in Service Worker API in Google Chrome prior to 1122023-04-19
GHSA
GHSA-x223-wmx3-frr5: Out of bounds memory access in Service Worker API in Google Chrome prior to 1122023-04-19

📋Vendor Advisories

3
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-21342023-05-12
Microsoft
Chromium: CVE-2023-2134 Out of bounds memory access in Service Worker API2023-04-11
Debian
CVE-2023-2134: chromium - Out of bounds memory access in Service Worker API in Google Chrome prior to 112....2023