CVE-2023-4074: Use after free in Blink Task Scheduling
Chromium: CVE-2023-4074 Use after free in Blink Task Scheduling
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Use after free in Blink Task Scheduling in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4074?
CVE-2023-4074 is a vulnerability found in Blink Task Scheduling in Google Chrome prior to version 115.0.5790.170.
How can a remote attacker exploit CVE-2023-4074?
A remote attacker can potentially exploit CVE-2023-4074 by using a crafted HTML page to trigger heap corruption.
What is the severity of CVE-2023-4074?
The severity of CVE-2023-4074 is rated as High (8.8).
Which software versions are affected by CVE-2023-4074?
Google Chrome versions prior to 115.0.5790.170 and Microsoft Edge (Chromium-based) versions prior to 115.0.1901.200 are affected.
How can I fix CVE-2023-4074?
You can fix CVE-2023-4074 by updating Google Chrome to version 115.0.5790.170 or upgrading Microsoft Edge (Chromium-based) to version 115.0.1901.200.