CVE-2023-0473
Summary
| CVE | CVE-2023-0473 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-30 09:15:00 UTC |
| Updated | 2023-02-06 21:40:00 UTC |
| Description | Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) |
Risk And Classification
Problem Types: CWE-843
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Chrome Releases: Stable Channel Update for Desktop | MISC | chromereleases.googleblog.com | |
| cve-website | MISC | www.cve.org | |
| 1404639 - chromium - An open-source project to help move the web forward. - Monorail | MISC | crbug.com | |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181507 Debian Security Update for chromium (DSA 5328-1)
- 182850 Debian Security Update for chromium (CVE-2023-0473)
- 199185 Ubuntu Security Notification for Chromium Vulnerabilities (USN-5881-1)
- 283669 Fedora Security Update for chromium (FEDORA-2023-fd4786cc83)
- 377931 Google Chrome Prior to 109.0.5414.119 Multiple Vulnerabilities
- 377935 Microsoft Edge Based on Chromium Prior to 109.0.1518.70/ Extended Version 108.0.1462.95 has Multiple Vulnerabilities
- 691041 Free Berkeley Software Distribution (FreeBSD) Security Update for chromium (3d0a3eb0-9ca3-11ed-a925-3065ec8fd3ec)
- 753675 OpenSUSE Security Update for opera (openSUSE-SU-2023:0044-1)
- 754103 OpenSUSE Security Update for opera (openSUSE-SU-2023:0115-1)