8.8
CVSSv3

CVE-2023-2936

Published: 30/05/2023 Updated: 31/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Type Confusion in V8 in Google Chrome before 114.0.5735.90 allowed a remote malicious user to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure For the stable distribution (bullseye), these problems have been fixed in version 1140573590-2~deb11u1 For the upcoming stable distribution (bookworm), these problems have been fixed in versio ...
 The Chrome team is delighted to announce the promotion of Chrome 114 to the stable channel for Windows, Mac and Linux This will roll out over the coming days/weeksChrome 1140573590 (Linux and Mac), 1140573590/91( Windows) contains a number of fixes and improvements -- a list of changes is available in the log Watch out for upcom ...
Check Point Reference: CPAI-2023-1426 Date Published: 7 Jan 2024 Severity: High ...

Exploits

v8::internal::JSObject::SetAccessor does not check if the receiver is extensible before adding a new property A potential attacker can exploit the ability to extend non-extensible objects to achieve arbitrary code execution inside the renderer process Google Chrome version 1130567263 is affected ...