PT-2023-3017 · Google +3 · Google Chrome +3

Clément Lecigne

·

Published

2023-06-05

·

Updated

2025-05-14

·

CVE-2023-3079

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C

Name of the Vulnerable Software and Affected Versions:

Google Chrome versions prior to 114.0.5735.110

Description:

The issue is related to a type confusion in V8, which could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This could lead to arbitrary code execution. The Chromium security severity of this issue is High.

Recommendations:

For Google Chrome versions prior to 114.0.5735.110, update to version 114.0.5735.110 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable API endpoints or disabling the use of crafted HTML pages until the update is applied.

Exploit

Fix

Type Confusion

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4492
ALT-PU-2023-4766
ALT-PU-2023-4767
ALT-PU-2023-6351
BDU:2023-03080
CVE-2023-3079
DSA-5420-1
OPENSUSE-SU-2023:0123-1
OPENSUSE-SU-2023:0124-1
OPENSUSE-SU-2024:12985-1
OPENSUSE-SU-2024:13009-1
OPENSUSE-SU-2024:13100-1
OPENSUSE-SU-2024:13190-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Red Os