First published: Thu Jul 20 2023(Updated: )
Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium security severity: High)
Credit: chrome-cve-admin@google.com chrome-cve-admin@google.com . @ginggilBesel
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <115.0.5790.98 | |
Google Chrome OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-3729 is a vulnerability that exists in Google Chrome on ChromeOS prior to version 115.0.5790.131 and allows a remote attacker to potentially exploit heap corruption through crafted UI interactions.
The severity of CVE-2023-3729 is high, with a CVSS score of 8.8.
The vulnerability can be exploited by convincing a user to engage in specific UI interactions.
The affected software for CVE-2023-3729 is Google Chrome on ChromeOS prior to version 115.0.5790.131.
To fix the vulnerability, users should update their Google Chrome to version 115.0.5790.131 or later.