CVE-2023-3216: Type Confusion in V8
Chromium: CVE-2023-3216 Type Confusion in V8
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.109-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.109-1~deb12u1Fixed in 120.0.6099.109-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 114.0.5735.133 - Upgrade
Upgrade
Chromium (V8) used by Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 114.0.5735.133
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-3216?
The severity of CVE-2023-3216 is considered high due to the potential for exploitation through type confusion in the affected browsers.
Which software products are affected by CVE-2023-3216?
CVE-2023-3216 affects Google Chrome versions prior to 114.0.5735.133, Microsoft Edge (Chromium-based) prior to 114.0.1823.51, and specific versions of Chromium on Debian and Fedora.
How do I fix CVE-2023-3216?
To fix CVE-2023-3216, update your Google Chrome or Microsoft Edge to the latest version as per the respective vendor's guidelines.
When was CVE-2023-3216 reported?
CVE-2023-3216 was assigned by Chrome and is associated with updates released around June 2023.
What type of vulnerability is CVE-2023-3216?
CVE-2023-3216 is classified as a type confusion vulnerability, which can lead to unauthorized access and execution of malicious code.