CVE-2023-3729
published 2023-08-01CVE-2023-3729: Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.41%
33.4th percentile
Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 115.0.5790.98 | 115.0.5790.98 | |
| chrome | >= 115.0.5790.131 < 115.0.5790.131 | 115.0.5790.131 | |
| chrome_chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77rh-qgrp-wjrm: Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115
ghsa_unreviewed·2023-08-02
CVE-2023-3729 [HIGH] CWE-416 GHSA-77rh-qgrp-wjrm: Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115
Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium security severity: High)
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-3729
vendor_chrome·2023-07-20·CVSS 8.8
CVE-2023-3729 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-3729
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2023-3729
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-01
Published