CVE-2023-0128: Use after free in Overview Mode
Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-0128?
The severity of CVE-2023-0128 is high.
What is the vulnerability ID of Google Chrome on Chrome OS prior to 109.0.5414.74?
The vulnerability ID of Google Chrome on Chrome OS prior to 109.0.5414.74 is CVE-2023-0128.
How does the Use after free vulnerability in Overview Mode in Google Chrome on Chrome OS work?
The Use after free vulnerability in Overview Mode in Google Chrome on Chrome OS allows a remote attacker who convinces a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
How can I fix the vulnerability in Google Chrome on Chrome OS?
To fix the vulnerability, update Google Chrome to version 109.0.5414.74 or later.
Is Google Chrome OS vulnerable to CVE-2023-0128?
No, Google Chrome OS is not vulnerable to CVE-2023-0128.