Severity
8.8HIGHNVD
EPSS
0.3%
top 47.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateJun 18

Description

Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome113.0.5672.114113.0.5672.114
NVDgoogle/chrome< 113.0.5672.114

🔴Vulnerability Details

1
GHSA
GHSA-p36v-2c7w-2x8f: Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 1132023-05-12

📋Vendor Advisories

7
Red Hat
kernel: HID: steam: Prevent NULL pointer dereference in steam_{recv,send}_report2025-06-18
Red Hat
kernel: gadgetfs: ep_io - wait until IRQ finishes2025-06-18
Red Hat
kernel: ASoC: mediatek: mt8173: Fix refcount leak in mt8173_rt5650_rt5676_dev_probe2025-06-18
Red Hat
kernel: usb: aspeed-vhub: Fix refcount leak bug in ast_vhub_init_desc()2025-06-18
Red Hat
kernel: icmp: Fix a data-race around sysctl_icmp_errors_use_inbound_ifaddr.2025-02-26