Google · Google Chrome · CVE-2023-0134
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 109.0.5414.74
**Description**
The issue is related to a use after free vulnerability in the Cart extension of Google Chrome, which can be exploited by an attacker who convinces a user to install a malicious extension. This can potentially lead to heap corruption via database corruption and a crafted HTML page, allowing the attacker to access confidential data, compromise its integrity, and cause a denial of service.
**Recommendations**
For Google Chrome versions prior to 109.0.5414.74, update to version 109.0.5414.74 or later to resolve the issue. As a temporary workaround, consider disabling the Cart extension until a patch is available. Restrict access to the Cart extension to minimize the risk of exploitation. Avoid using the Cart extension with crafted HTML pages until the issue is resolved.