CVE-2023-2931: Use after free in PDF
Chromium: CVE-2023-2931 Use after free in PDF
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-2931?
CVE-2023-2931 has been classified as a high-severity vulnerability due to its potential for causing exploitation through a use-after-free condition.
How do I fix CVE-2023-2931?
To mitigate CVE-2023-2931, users should update Google Chrome, Microsoft Edge Chromium, or Debian's Chromium packages to the latest available versions.
Which software versions are affected by CVE-2023-2931?
CVE-2023-2931 affects Google Chrome versions up to 114.0.5735.90, Microsoft Edge (Chromium-based) versions up to 114.0.1823.37, and Debian's Chromium version up to 90.0.4430.212.
Is Microsoft Edge (Chromium-based) affected by CVE-2023-2931?
Yes, Microsoft Edge (Chromium-based) is affected by CVE-2023-2931 and requires an update to the latest version to address the vulnerability.
What type of vulnerability is CVE-2023-2931?
CVE-2023-2931 is categorized as a 'use after free' vulnerability, which can lead to security issues such as memory corruption.