CVE-2023-3729: free in Ash
Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-3729?
CVE-2023-3729 is a vulnerability that exists in Google Chrome on ChromeOS prior to version 115.0.5790.131 and allows a remote attacker to potentially exploit heap corruption through crafted UI interactions.
What is the severity of CVE-2023-3729?
The severity of CVE-2023-3729 is high, with a CVSS score of 8.8.
How can the vulnerability be exploited?
The vulnerability can be exploited by convincing a user to engage in specific UI interactions.
What is the affected software for CVE-2023-3729?
The affected software for CVE-2023-3729 is Google Chrome on ChromeOS prior to version 115.0.5790.131.
How can the vulnerability be fixed?
To fix the vulnerability, users should update their Google Chrome to version 115.0.5790.131 or later.