CVE-2023-1227: Use after free in Core
Published Jul 31, 2022
·Updated
Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
Credit
@@ginggilBesel
Affected Software
5 affected componentsFixes available
Google Chrome<111.0.5563.64
111.0.5563.64
All of the following
Google Chrome<111.0.5563.64
Google Linux And Chrome Os
Google Chrome<111.0.5563.64
Google Linux And Chrome Os
Event History
Jul 31, 2022
CVE Published
12:00 AM
Mar 7, 2023
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-1213
- CVE-2023-1214
- CVE-2023-1215
- CVE-2023-1216
- CVE-2023-1217
- CVE-2023-1218
- CVE-2023-1219
- CVE-2023-1220
- CVE-2023-1221
- CVE-2023-1222
- CVE-2023-1223
- CVE-2023-1224
- CVE-2023-1225
- CVE-2023-1226
- CVE-2023-1228
- CVE-2023-1229
- CVE-2023-1230
- CVE-2023-1231
- CVE-2023-2314
- CVE-2023-1232
- CVE-2023-1233
- CVE-2023-1234
- CVE-2023-1235
- CVE-2023-1236
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-1227.
2
What is the severity of CVE-2023-1227?
CVE-2023-1227 has a severity rating of 8.8 (High).
3
How does CVE-2023-1227 affect Google Chrome on Lacros?
CVE-2023-1227 affects Google Chrome on Lacros versions prior to 111.0.5563.64.
4
How can a remote attacker exploit CVE-2023-1227?
A remote attacker can potentially exploit CVE-2023-1227 by convincing a user to engage in specific UI interaction, leading to heap corruption via crafted UI interaction.
5
Is Google Linux and Chrome OS affected by CVE-2023-1227?
No, Google Linux and Chrome OS is not vulnerable to CVE-2023-1227.