PT-2023-3330 · Google+2 · Google Chrome+2
Avaue
·
Publicado
2023-01-10
·
Atualizado
2024-06-15
·
CVE-2023-0137
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome on Chrome OS versions prior to 109.0.5414.74
Description
The issue is related to a heap buffer overflow in Platform Apps, which could be exploited by an attacker who convinces a user to install a malicious extension. This could potentially lead to heap corruption via a crafted HTML page. The attacker, acting remotely, could install arbitrary extensions using a specially crafted HTML page.
Recommendations
For Google Chrome on Chrome OS versions prior to 109.0.5414.74, update to version 109.0.5414.74 or later to resolve the issue. As a temporary workaround, consider restricting the installation of extensions to minimize the risk of exploitation. Avoid using crafted HTML pages that could trigger the heap buffer overflow until the issue is resolved.
Correção
Memory Corruption
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Astra Linux
Google Chrome