CVE-2023-3422: Use after free in Guest View
Chromium: CVE-2023-3422 Use after free in Guest View
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1Fixed in 118.0.5993.70-1~deb11u1Fixed in 116.0.5845.180-1~deb12u1Fixed in 118.0.5993.70-1~deb12u1Fixed in 118.0.5993.70-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 114.0.5735.198 - Upgrade
Upgrade
Chromium (Guest View)to a version that resolves this vulnerability.Fixed in 114.0.5735.198 - Upgrade
Upgrade
Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 114.0.5735.198
Event History
Frequently Asked Questions
What is CVE-2023-3422?
CVE-2023-3422 is a vulnerability in Chromium that allows an attacker to potentially exploit heap corruption via a crafted HTML page in Google Chrome versions prior to 114.0.5735.198.
What is the severity of CVE-2023-3422?
The severity of CVE-2023-3422 is high.
Which software is affected by CVE-2023-3422?
Microsoft Edge versions prior to 114.0.1823.67 and Microsoft Edge (Chromium-based) versions before 117.0.5938.62-1~deb11u1 or 114.0.5735.198-1~deb12u1 are affected.
How can CVE-2023-3422 be fixed in Microsoft Edge?
To fix CVE-2023-3422 in Microsoft Edge, update to version 114.0.1823.67 or a later version.
How can CVE-2023-3422 be fixed in Microsoft Edge (Chromium-based)?
To fix CVE-2023-3422 in Microsoft Edge (Chromium-based), update to version 117.0.5938.62-1~deb11u1 or 114.0.5735.198-1~deb12u1 or a later version.
How can CVE-2023-3422 be fixed in the Debian Chromium package?
To fix CVE-2023-3422 in the Debian Chromium package, update to version 117.0.5938.62-1~deb10u1 or 112.0.5615.138-1~deb11u1 or a later version.