CVE-2023-2458: free in ChromeOS Ash
Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: High)
Credit
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2458?
CVE-2023-2458 is a vulnerability in the ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114.
What is the severity of CVE-2023-2458?
The severity of CVE-2023-2458 is high, with a severity value of 8.8.
How does CVE-2023-2458 affect Google Chrome?
CVE-2023-2458 allows a remote attacker to exploit heap corruption via specific UI interaction in the ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114.
How can I fix CVE-2023-2458?
To fix CVE-2023-2458, update Google Chrome to version 113.0.5672.114 or later.
Where can I find more information about CVE-2023-2458?
You can find more information about CVE-2023-2458 in the references: [link1] and [link2].