CVE-2023-0135: Use after free in Cart
Published Nov 18, 2022
·Updated
Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML page. (Chromium security severity: Medium)
Credit
Chaoyuan Peng@@ret2happy
Affected Software
2 affected componentsFixes available
Google Chrome<109.0.5414.74
109.0.5414.74
Google Chrome<109.0.5414.74
Event History
Nov 18, 2022
CVE Published
12:00 AM
Jan 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-0135?
CVE-2023-0135 has a medium severity level as assessed by Chromium security.
2
How do I fix CVE-2023-0135?
To fix CVE-2023-0135, update Google Chrome to version 109.0.5414.74 or newer.
3
What causes CVE-2023-0135?
CVE-2023-0135 is caused by a use after free vulnerability in the Cart feature of Google Chrome.
4
What potential impact does CVE-2023-0135 have?
CVE-2023-0135 could allow an attacker to exploit heap corruption through a malicious extension and crafted HTML.
5
Is CVE-2023-0135 specific to certain versions of Google Chrome?
Yes, CVE-2023-0135 affects Google Chrome versions prior to 109.0.5414.74.