PT-2023-2347 · Google+4 · V8+5

Clément Lecigne

·

Published

2023-04-14

·

Updated

2025-12-14

·

CVE-2023-2033

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 112.0.5615.121
Description The issue is related to a type confusion in V8, which can allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This can lead to arbitrary code execution. The vulnerability is considered high severity by Chromium. There is evidence that this issue has been exploited in the wild.
Recommendations For versions prior to 112.0.5615.121, update to version 112.0.5615.121 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable API endpoints until the update is applied. Avoid using crafted HTML pages that could exploit the type confusion in V8. At the moment, there is no additional information about other mitigation measures.

Exploit

Fix

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2023-1659
ALT-PU-2023-1670
ALT-PU-2023-1749
ALT-PU-2023-1928
ALT-PU-2023-1998
ALT-PU-2023-2011
ALT-PU-2023-2021
ALT-PU-2023-4119
ALT-PU-2023-5790
ALT-PU-2024-14286
ALT-PU-2024-14830
BDU:2023-02114
CVE-2023-2033
DSA-5390-1
OPENSUSE-SU-2023:0092-1
OPENSUSE-SU-2023:0114-1
OPENSUSE-SU-2023:0115-1
OPENSUSE-SU-2023_0114-1
OPENSUSE-SU-2023_0115-1
OPENSUSE-SU-2024:12867-1
OPENSUSE-SU-2024:12897-1
OPENSUSE-SU-2024:12948-1
OPENSUSE-SU-2024:12963-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Red Os
Suse
V8