CVE-2023-2722: Use after free in Autofill UI
Chromium: CVE-2023-2722 Use after free in Autofill UI
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-2722?
CVE-2023-2722 is a vulnerability in Autofill UI in Google Chrome on Android prior to version 113.0.5672.126 that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
What is the severity of CVE-2023-2722?
The severity of CVE-2023-2722 is High.
How can a remote attacker exploit CVE-2023-2722?
A remote attacker can potentially exploit CVE-2023-2722 by using a crafted HTML page.
Which software versions are affected by CVE-2023-2722?
Google Chrome on Android versions prior to 113.0.5672.126 are affected by CVE-2023-2722.
How can I fix CVE-2023-2722?
To fix CVE-2023-2722, update your Google Chrome on Android to version 113.0.5672.126 or later.