CVE-2023-2457: High severity google chrome (trace event) vulnerability
Published May 9, 2023
·Updated
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)
Credit
raven at KunLun lab
Affected Software
4 affected components
All of the following
Google Chrome<113.0.5672.114
Google Chrome OS
Google Chrome<113.0.5672.114
Google Chrome OS
Event History
May 9, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeakness
May 12, 2023
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-2457?
The severity of CVE-2023-2457 is High.
2
What is the affected software for CVE-2023-2457?
The affected software for CVE-2023-2457 is Google Chrome on ChromeOS prior to 113.0.5672.114.
3
How can a remote attacker exploit CVE-2023-2457?
A remote attacker can potentially exploit CVE-2023-2457 by using a crafted audio file to cause heap corruption.
4
How can I fix CVE-2023-2457?
To fix CVE-2023-2457, update Google Chrome to version 113.0.5672.114 or later.
5
Is Google Chrome OS vulnerable to CVE-2023-2457?
No, Google Chrome OS is not vulnerable to CVE-2023-2457.