CVE-2023-3730: Use after free in Tab Groups
Chromium: CVE-2023-3730 Use after free in Tab Groups
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-3730?
CVE-2023-3730 is a vulnerability in Chromium that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
What is the severity of CVE-2023-3730?
CVE-2023-3730 has a severity rating of High (8.8) according to Chromium security severity.
How can CVE-2023-3730 be exploited?
CVE-2023-3730 can be exploited by convincing a user to engage in specific UI interactions with a crafted HTML page.
Which software versions are affected by CVE-2023-3730?
Google Chrome prior to version 115.0.5790.98 and Microsoft Edge (Chromium-based) prior to version 115.0.1901.183 are affected by CVE-2023-3730.
How can I fix CVE-2023-3730?
To fix CVE-2023-3730, update Google Chrome to version 115.0.5790.98 or later and update Microsoft Edge (Chromium-based) to version 115.0.1901.183 or later.