CVE-2023-1217: Stack buffer overflow in Crash reporting
Stack buffer overflow in Crash reporting in Google Chrome on Windows prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-1213
- CVE-2023-1214
- CVE-2023-1215
- CVE-2023-1216
- CVE-2023-1218
- CVE-2023-1219
- CVE-2023-1220
- CVE-2023-1221
- CVE-2023-1222
- CVE-2023-1223
- CVE-2023-1224
- CVE-2023-1225
- CVE-2023-1226
- CVE-2023-1227
- CVE-2023-1228
- CVE-2023-1229
- CVE-2023-1230
- CVE-2023-1231
- CVE-2023-2314
- CVE-2023-1232
- CVE-2023-1233
- CVE-2023-1234
- CVE-2023-1235
- CVE-2023-1236
Frequently Asked Questions
What is the severity of CVE-2023-1217?
CVE-2023-1217 has a security severity rating of High due to its potential to allow remote attackers to obtain sensitive information.
What should I do to mitigate CVE-2023-1217?
To mitigate CVE-2023-1217, update Google Chrome to version 111.0.5563.64 or later.
How does CVE-2023-1217 exploit Chrome's crash reporting?
CVE-2023-1217 exploits a stack buffer overflow in the crash reporting feature, enabling attackers to access process memory.
Who is affected by CVE-2023-1217?
Users of Google Chrome on Windows prior to version 111.0.5563.64 are affected by CVE-2023-1217.
Can CVE-2023-1217 be exploited through any HTML page?
Yes, CVE-2023-1217 can be exploited via a crafted HTML page that targets the renderer process.