8.8
CVSSv3

CVE-2023-0137

Published: 10/01/2023 Updated: 25/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS before 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure For the stable distribution (bullseye), this problem has been fixed in version 1090541474-2~deb11u1 We recommend that you upgrade your chromium packages For the detailed security status of ch ...
The Stable channel is being updated to 1090541494 (Platform version: 15236660) for most ChromeOS devices and will be rolled out over the next few daysFor Chrome browser fixes, see the Chrome Desktop release announcementIf you find new issues, please let us know one of the following ways:File a bug Visit our Chrome OS ...
The Chrome team is delighted to announce the promotion of Chrome 109 to the stable channel for Windows, Mac and Linux This will roll out over the coming days/weeksChrome 1090541474 (linux),1090541474/75( Windows) and 1090541487(Mac)  contains a number of fixes and improvements -- a list of changes is available i ...