CVE-2023-6509
published 2023-12-06CVE-2023-6509: Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.99%
58.7th percentile
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 120.0.6099.71-1~deb11u1 | 120.0.6099.71-1~deb11u1 |
| chromium | chromium | >= 0 < 120.0.6099.71-1~deb12u1 | 120.0.6099.71-1~deb12u1 |
| chromium | chromium | >= 0 < 120.0.6099.71-1 | 120.0.6099.71-1 |
| chromium | chromium | >= 0 < 120.0.6099.71-1 | 120.0.6099.71-1 |
| debian | chromium | < chromium 120.0.6099.71-1~deb12u1 (bookworm) | chromium 120.0.6099.71-1~deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 120.0.6099.62 | 120.0.6099.62 | |
| chrome | >= 120.0.6099.62 < 120.0.6099.62 | 120.0.6099.62 | |
| chrome_chrome | — | — | |
| mozilla | firefox | >= 0 < 120.0.1+build1-0ubuntu0.20.04.1 | 120.0.1+build1-0ubuntu0.20.04.1 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-6509
vendor_chrome·2024-02-01·CVSS 8.8
CVE-2023-6509 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2023-6509
Long Term Support Channel Update for ChromeOS
CVE-2023-6509
Microsoft
Chromium: CVE-2023-6509 Use after free in Side Panel Search
vendor_msrc·2023-12-12·CVSS 8.8
CVE-2023-6509 [HIGH] Chromium: CVE-2023-6509 Use after free in Side Panel Search
Chromium: CVE-2023-6509 Use after free in Side Panel Search
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
Debian
CVE-2023-6509: chromium - Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allo...
vendor_debian·2023·CVSS 8.8
CVE-2023-6509 [HIGH] CVE-2023-6509: chromium - Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allo...
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099.71-1~deb11u1)
forky: resolved (fixed in 120.0.6099.71-1)
sid: resolved (fixed in 120.0.6099.71-1)
trixie: resolved (fixed in 120.0.6099.71-1)
OSV
CVE-2023-6509: Use after free in Side Panel Search in Google Chrome prior to 120
osv·2023-12-06·CVSS 8.8
CVE-2023-6509 [HIGH] CVE-2023-6509: Use after free in Side Panel Search in Google Chrome prior to 120
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
GHSA
GHSA-qw8w-gvwg-qc22: Use after free in Side Panel Search in Google Chrome prior to 120
ghsa_unreviewed·2023-12-06
CVE-2023-6509 [HIGH] CWE-416 GHSA-qw8w-gvwg-qc22: Use after free in Side Panel Search in Google Chrome prior to 120
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
OSV
firefox regressions
osv·2023-12-04·CVSS 6.5
CVE-2023-6206 firefox regressions
firefox regressions
USN-6509-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-6206,
CVE-2023-6210, CVE-2023-6211, CVE-2023-6212, CVE-2023-6213)
It was discovered that Firefox did not properly manage memory when
images were created on the canvas element. An attacker could potentially
exploit this issue to obtain sensitive information. (CVE-2023-6204)
It discovered that Firefox incorrectly
No detection rules found.
No public exploits indexed.
Trendmicro
The December 2023 Security Update Review
blogs_trendmicro·2023-12-12
The December 2023 Security Update Review
# The December 2023 Security Update Review
Get the December 2023 security update and review.
By: Zero Day Initiative
2023/12/12
Read time: ( words)
Save to Folio
It’s the final patch Tuesday of 2023, and Apple, Adobe, and Microsoft have released their latest security offerings. Take a break from your holiday hustle and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
Apple Patches for December 2023
Apple kicked off the December release cycle with patches for iOS and iPadOS with eight CVEs. Two of these CVEs in Webkit are reported as being under active attack on iOS versions 16.7.1 and older. If you’re using an older iPhone or iPad, you should definitely update your device immediately. If you’re using a dev
Bleepingcomputer
Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
blogs_bleepingcomputer·2023-12-12·CVSS 5.5
[MEDIUM] Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
## Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
## Lawrence Abrams
10 Elevation of Privilege Vulnerabilities
8 Remote Code Execution Vulnerabilities
6 Information Disclosure Vulnerabilities
5 Denial of Service Vulnerabilities
5 Spoofing Vulnerabilities
The total count of 34 flaws does not include 8 Microsoft Edge flaws fixed on December 7th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5033375 cumulative update and Windows 10 KB5033372 cumulative update .
## One publicly disclosed zero-day fixed
This month's Patch Tuesday fixes one AMD zero-day vulnerability disclosed in August that previously remained unpatched.
The ' CVE-2023-20588 - AMD: CVE-2023-20588 AMD Speculative Leaks ' vul
https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/1494565https://lists.fedoraproject.org/archives/list/[email protected]/message/MMHY76AWPA46MAFXPWDGJX6FEGXZVR5Z/https://lists.fedoraproject.org/archives/list/[email protected]/message/RI3UHCTFH6KWAJGDZ2TOLT6VHKW53WCC/https://security.gentoo.org/glsa/202401-34https://www.debian.org/security/2023/dsa-5573https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/1494565https://lists.fedoraproject.org/archives/list/[email protected]/message/MMHY76AWPA46MAFXPWDGJX6FEGXZVR5Z/https://lists.fedoraproject.org/archives/list/[email protected]/message/RI3UHCTFH6KWAJGDZ2TOLT6VHKW53WCC/https://security.gentoo.org/glsa/202401-34https://www.debian.org/security/2023/dsa-5573
2023-12-06
Published