First published: Mon Nov 07 2022(Updated: )
Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and specific interactions. (Chromium security severity: High)
Credit: asnine chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <109.0.5414.74 | |
Google Chrome | <109.0.5414.74 | 109.0.5414.74 |
<109.0.5414.74 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-0129 has a severity rating of High due to the potential for heap corruption exploitation.
To mitigate CVE-2023-0129, users should update Google Chrome to version 109.0.5414.74 or later.
CVE-2023-0129 is caused by a heap buffer overflow in the Network Service of Google Chrome.
CVE-2023-0129 affects users of Google Chrome versions prior to 109.0.5414.74.
Yes, CVE-2023-0129 can potentially be exploited remotely if a user installs a malicious extension.