CVE-2023-2930: Use after free in Extensions
Chromium: CVE-2023-2930 Use after free in Extensions
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-2930?
The severity of CVE-2023-2930 is classified as high due to its potential to allow use-after-free vulnerabilities.
How do I fix CVE-2023-2930?
To fix CVE-2023-2930, update your Google Chrome or Microsoft Edge (Chromium-based) to the latest version as recommended.
Which software is affected by CVE-2023-2930?
CVE-2023-2930 affects Google Chrome versions up to 114.0.5735.90 and Microsoft Edge (Chromium-based) versions prior to the latest update.
What causes CVE-2023-2930?
CVE-2023-2930 is caused by a use-after-free vulnerability within Google Chrome's processing of certain resources.
Is CVE-2023-2930 present in older versions of Chromium?
Yes, CVE-2023-2930 is present in older versions of Chromium prior to the fixes included in updates released after May 2023.