CVE-2023-4430: Use after free in Vulkan
Chromium: CVE-2023-4430: Use after free in Vulkan
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4430?
CVE-2023-4430 is a vulnerability in Chromium that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Which software is affected by CVE-2023-4430?
CVE-2023-4430 affects Google Chrome versions up to and including 116.0.5845.110, Edge (Chromium-based) versions prior to 116.0.1938.62, and Microsoft Edge versions up to 116.0.1938.62.
How severe is the CVE-2023-4430 vulnerability?
The severity of CVE-2023-4430 is high with a CVSS score of 8.8.
How can I fix the CVE-2023-4430 vulnerability?
To fix the CVE-2023-4430 vulnerability, update your software to Google Chrome version 116.0.5845.110 or later, Microsoft Edge (Chromium-based) version 116.0.1938.62 or later, or Microsoft Edge version 116.0.1938.62 or later.
Where can I find more information about CVE-2023-4430?
You can find more information about CVE-2023-4430 on the Microsoft Security Response Center (MSRC) website, Debian Security Tracker, and the Google Chrome Releases blog.