PT-2023-6643 · Google+3 · Google Chrome+3
Darknavy
·
Publicado
2023-10-31
·
Atualizado
2024-11-29
·
CVE-2023-5849
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 119.0.6045.105
Description
The issue is related to an integer overflow in the USB interface of Google Chrome, which can lead to heap corruption. A remote attacker can potentially exploit this issue via a crafted HTML page, allowing them to execute arbitrary code. The severity of this issue is classified as High by Chromium.
Recommendations
For Google Chrome versions prior to 119.0.6045.105, update to version 119.0.6045.105 or later to resolve the issue. As a temporary workaround, consider restricting access to USB interfaces in Google Chrome until a patch is applied. Avoid using specially crafted HTML pages that could exploit the integer overflow in the USB interface.
Exploit
Correção
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Astra Linux
Google Chrome
Red Os