CVE-2023-1815: Use after free in Networking APIs
Chromium: CVE-2023-1815 Use after free in Networking APIs
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-1815?
CVE-2023-1815 is a vulnerability in Chromium that allows a remote attacker to exploit heap corruption via a crafted HTML page.
What is the severity of CVE-2023-1815?
The severity of CVE-2023-1815 is rated as Medium.
Which software is affected by CVE-2023-1815?
Microsoft Edge (Chromium-based) and Google Chrome versions prior to 112.0.5615.49 are affected by CVE-2023-1815.
How can I fix CVE-2023-1815?
Update Microsoft Edge (Chromium-based) to version 112.0.1722.34 or later, or update Google Chrome to version 112.0.5615.49 or later.
Where can I find more information about CVE-2023-1815?
You can find more information about CVE-2023-1815 at the following references: [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-1815](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-1815), [https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.html](https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.html), [https://crbug.com/1278708](https://crbug.com/1278708).