CVE-2023-4071: Heap buffer overflow in Visuals
Chromium: CVE-2023-4071 Heap buffer overflow in Visuals
Other sources
Heap buffer overflow in Visuals in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-4071.
What is the severity of CVE-2023-4071?
The severity of CVE-2023-4071 is high with a CVSS score of 8.8.
What is the affected software?
The affected software includes Google Chrome prior to version 115.0.5790.170, Microsoft Edge prior to version 115.0.1901.200, and Chromium-based Microsoft Edge.
How can a remote attacker potentially exploit this vulnerability?
A remote attacker can potentially exploit this vulnerability by using a crafted HTML page to trigger a heap buffer overflow in Visuals.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Chrome Releases blog, the Chromium bug tracker, and the Debian Security Advisory.