CVE-2023-0474
Published on: Not Yet Published
Last Modified on: 02/20/2023 09:28:57 AM UTC
Certain versions of Chrome from Google contain the following vulnerability:
Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a Chrome web app. (Chromium security severity: Medium)
- CVE-2023-0474 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Google - Chrome version < 109.0.5414.119
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
cve-website | www.cve.org text/html |
![]() |
1400841 - chromium - An open-source project to help move the web forward. - Monorail | crbug.com text/html |
![]() |
Chrome Releases: Stable Channel Update for Desktop | chromereleases.googleblog.com text/html |
![]() |
Related QID Numbers
- 181507 Debian Security Update for chromium (DSA 5328-1)
- 199185 Ubuntu Security Notification for Chromium Vulnerabilities (USN-5881-1)
- 283669 Fedora Security Update for chromium (FEDORA-2023-fd4786cc83)
- 377931 Google Chrome Prior to 109.0.5414.119 Multiple Vulnerabilities
- 377935 Microsoft Edge Based on Chromium Prior to 109.0.1518.70/ Extended Version 108.0.1462.95 has Multiple Vulnerabilities
- 691041 Free Berkeley Software Distribution (FreeBSD) Security Update for chromium (3d0a3eb0-9ca3-11ed-a925-3065ec8fd3ec)
- 753675 OpenSUSE Security Update for opera (openSUSE-SU-2023:0044-1)
Exploit/POC from Github
Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to inst…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Chrome | All | All | All | All |
- cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Potentially Critical CVE Detected! CVE-2023-0474 Use after free in GuestView in Google Chrome prior to 109.0.5414.1… twitter.com/i/web/status/1… | 2023-01-24 20:56:00 |
![]() |
Google Chrome code execution | CVE-2023-0474 - redpacketsecurity.com/google-chrome-… #CVE #Vulnerability #OSINT #ThreatIntel #Cyber | 2023-01-25 10:01:36 |
![]() |
MS-ISAC CYBERSECURITY ADVISORY – Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution – PATCH: NOW | 2023-01-25 13:44:05 |