CVE-2023-5476: Use after free in Blink History
Chromium: CVE-2023-5476 Use after free in Blink History
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-5476.
What is the severity of CVE-2023-5476?
The severity of CVE-2023-5476 is high with a severity value of 8.8.
What software is affected by CVE-2023-5476?
Google Chrome versions prior to 118.0.5993.70 are affected by CVE-2023-5476.
How can a remote attacker exploit this vulnerability?
A remote attacker can potentially exploit this vulnerability by using a crafted HTML page to cause heap corruption.
Is there a fix available for CVE-2023-5476?
Yes, a fix is available for CVE-2023-5476. It is recommended to update to Google Chrome version 118.0.5993.70 or later.