CVE-2023-2313
published 2023-07-29CVE-2023-2313: Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.53%
41.2th percentile
Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 112.0.5615.49-2~deb11u2 | 112.0.5615.49-2~deb11u2 |
| chromium | chromium | >= 0 < 112.0.5615.49-1 | 112.0.5615.49-1 |
| chromium | chromium | >= 0 < 112.0.5615.49-1 | 112.0.5615.49-1 |
| chromium | chromium | >= 0 < 112.0.5615.49-1 | 112.0.5615.49-1 |
| debian | chromium | < chromium 112.0.5615.49-1 (bookworm) | chromium 112.0.5615.49-1 (bookworm) |
| chrome | < 112.0.5615.49 | 112.0.5615.49 | |
| chrome | >= 112.0.5615.49 < 112.0.5615.49 | 112.0.5615.49 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2023-1810
vendor_chrome·2023-04-04·CVSS 8.8
CVE-2023-1810 [HIGH] Stable Channel Update for Desktop: CVE-2023-1810
Stable Channel Update for Desktop
CVE-2023-1810: Heap buffer overflow in Visuals. Reported by Weipeng Jiang (@Krace) of VRI on 2023-02-08 [$3000][ 1420510 ] High CVE-2023-1811: Use after free in Frames
Reported by Thomas Orlita on 2023-03-01 [$TBD][ 1335974 ] High CVE-2023-2313: Inappropriate implementation in Sandbox
Severity: high
Debian
CVE-2023-2313: chromium - Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112...
vendor_debian·2023·CVSS 8.8
CVE-2023-2313 [HIGH] CVE-2023-2313: chromium - Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112...
Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.49-1)
sid: resolved (fixed in 112.0.5615.49-1)
trixie: resolved (fixed in 112.0.5615.49-1)
GHSA
GHSA-mq7w-mj9p-33fc: Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112
ghsa_unreviewed·2023-07-29
CVE-2023-2313 [HIGH] GHSA-mq7w-mj9p-33fc: Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112
Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)
OSV
CVE-2023-2313: Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112
osv·2023-07-29·CVSS 8.8
CVE-2023-2313 [HIGH] CVE-2023-2313: Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112
Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/1335974https://lists.fedoraproject.org/archives/list/[email protected]/message/2LE64KGGOISKPKMYROSDT4K6QFVDIRF6/https://lists.fedoraproject.org/archives/list/[email protected]/message/B6SAST6CB5KKCQKH75ER2UQ3ICYPHCIZ/https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/1335974https://lists.fedoraproject.org/archives/list/[email protected]/message/2LE64KGGOISKPKMYROSDT4K6QFVDIRF6/https://lists.fedoraproject.org/archives/list/[email protected]/message/B6SAST6CB5KKCQKH75ER2UQ3ICYPHCIZ/
2023-07-29
Published