PT-2023-3330 · Google+2 · Google Chrome+2
Avaue
·
Published
2023-01-10
·
Updated
2024-06-15
·
CVE-2023-0137
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome on Chrome OS versions prior to 109.0.5414.74
Description
The issue is related to a heap buffer overflow in Platform Apps, which could be exploited by an attacker who convinces a user to install a malicious extension. This could potentially lead to heap corruption via a crafted HTML page. The attacker, acting remotely, could install arbitrary extensions using a specially crafted HTML page.
Recommendations
For Google Chrome on Chrome OS versions prior to 109.0.5414.74, update to version 109.0.5414.74 or later to resolve the issue. As a temporary workaround, consider restricting the installation of extensions to minimize the risk of exploitation. Avoid using crafted HTML pages that could trigger the heap buffer overflow until the issue is resolved.
Fix
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Google Chrome