CVE-2023-2725: Use after free in Guest View
Chromium: CVE-2023-2725 Use after free in Guest View
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-2725?
CVE-2023-2725 is a vulnerability in Chromium that allows an attacker to exploit heap corruption via a crafted HTML page.
What is the severity of CVE-2023-2725?
CVE-2023-2725 has a severity rating of High (8.8) according to the Chromium security severity rating.
Which software are affected by CVE-2023-2725?
CVE-2023-2725 affects Google Chrome, Microsoft Edge (Chromium-based), Microsoft Edge (Chromium-based) Extended Stable, Microsoft Edge, Debian Debian Linux, and Fedoraproject Fedora.
How can I fix the CVE-2023-2725 vulnerability?
To fix the CVE-2023-2725 vulnerability, update Chrome to version 113.0.5672.126 or later, or refer to the security advisories provided by Microsoft, Debian, and Fedoraproject for the respective affected software.
Where can I find more information about CVE-2023-2725?
You can find more information about CVE-2023-2725 on the Microsoft Security Response Center website, Google Chrome Releases blog, and Chromium bug tracker.