First published: Tue May 09 2023(Updated: )
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)
Credit: chrome-cve-admin@google.com raven at KunLun lab chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <113.0.5672.114 | |
Google Chrome OS | ||
All of | ||
Google Chrome | <113.0.5672.114 | |
Google Chrome OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2457 is High.
The affected software for CVE-2023-2457 is Google Chrome on ChromeOS prior to 113.0.5672.114.
A remote attacker can potentially exploit CVE-2023-2457 by using a crafted audio file to cause heap corruption.
To fix CVE-2023-2457, update Google Chrome to version 113.0.5672.114 or later.
No, Google Chrome OS is not vulnerable to CVE-2023-2457.