CVE-2023-5218: Use after free in Site Isolation
Chromium: CVE-2023-5218 Use after free in Site Isolation
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-5218?
CVE-2023-5218 refers to a use-after-free vulnerability in Site Isolation in Google Chrome, which could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page.
What is the severity of CVE-2023-5218?
CVE-2023-5218 has a severity rating of 8.8 (high severity).
Which software products are affected by CVE-2023-5218?
Microsoft Edge (Chromium-based), Microsoft Edge (version before 118.0.2088.46), and Google Chrome (version before 118.0.5993.70) are affected by CVE-2023-5218.
How can I fix CVE-2023-5218?
To fix CVE-2023-5218, update your software to Microsoft Edge 118.0.2088.46 or later, or Google Chrome 118.0.5993.70 or later.
Where can I find more information about CVE-2023-5218?
You can find more information about CVE-2023-5218 at the following references: [1] [2] [3].