CVE-2023-1216: Use after free in DevTools
Published Feb 21, 2023
·Updated
Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Ganjiang Zhou@@refrain_areu(ChaMd5)
Affected Software
2 affected componentsFixes available
Google Chrome<111.0.5563.64
111.0.5563.64
Google Chrome<111.0.5563.64
Event History
Feb 21, 2023
CVE Published
12:00 AM
Mar 7, 2023
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-1213
- CVE-2023-1214
- CVE-2023-1215
- CVE-2023-1217
- CVE-2023-1218
- CVE-2023-1219
- CVE-2023-1220
- CVE-2023-1221
- CVE-2023-1222
- CVE-2023-1223
- CVE-2023-1224
- CVE-2023-1225
- CVE-2023-1226
- CVE-2023-1227
- CVE-2023-1228
- CVE-2023-1229
- CVE-2023-1230
- CVE-2023-1231
- CVE-2023-2314
- CVE-2023-1232
- CVE-2023-1233
- CVE-2023-1234
- CVE-2023-1235
- CVE-2023-1236
Frequently Asked Questions
1
What is the severity of CVE-2023-1216?
CVE-2023-1216 has a high severity rating due to its potential for allowing heap corruption.
2
How do I fix CVE-2023-1216?
To mitigate CVE-2023-1216, update Google Chrome to version 111.0.5563.64 or later.
3
Who is affected by CVE-2023-1216?
CVE-2023-1216 affects users of Google Chrome versions prior to 111.0.5563.64.
4
What type of vulnerability is CVE-2023-1216?
CVE-2023-1216 is classified as a use after free vulnerability in DevTools of Google Chrome.
5
Can CVE-2023-1216 be exploited remotely?
Yes, CVE-2023-1216 can potentially be exploited remotely if a user engages with a crafted HTML page.