First published: Sat Dec 10 2022(Updated: )
Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Credit: chrome-cve-admin@google.com avaue Buff3tts at S.S.L. chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <109.0.5414.74 | |
Google Chrome OS | ||
Google Chrome | <109.0.5414.74 | 109.0.5414.74 |
All of | ||
<109.0.5414.74 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-0137 is a heap buffer overflow vulnerability in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74.
An attacker can exploit CVE-2023-0137 by convincing a user to install a malicious extension and then exploiting heap corruption via a crafted HTML page.
The severity of CVE-2023-0137 is medium according to the Chromium security severity rating.
To fix CVE-2023-0137, update Google Chrome on Chrome OS to version 109.0.5414.74 or later.
Yes, you can find additional references for CVE-2023-0137 at the following links: [link1](https://chromereleases.googleblog.com/2023/01/stable-channel-update-for-desktop.html), [link2](https://crbug.com/1399904), [link3](https://security.gentoo.org/glsa/202305-10).