CVE-2023-5849: Integer overflow in USB
Chromium: CVE-2023-5849 Integer overflow in USB
Other sources
Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-5849?
CVE-2023-5849 is an integer overflow vulnerability in the USB component of Chromium.
What is the severity of CVE-2023-5849?
The severity of CVE-2023-5849 is High.
Which software is affected by CVE-2023-5849?
Microsoft Edge versions up to 119.0.2151.44 and Microsoft Edge (Chromium-based) are affected by CVE-2023-5849.
How can I fix CVE-2023-5849?
To fix CVE-2023-5849, update your Microsoft Edge browser to version 119.0.6045.105 or newer.
Where can I find more information about CVE-2023-5849?
More information about CVE-2023-5849 can be found in the references provided: [Google Chrome Releases](https://chromereleases.googleblog.com/2023/10/stable-channel-update-for-desktop_31.html), [Chromium Bug Tracker](https://crbug.com/1492384), and [Microsoft Security Response Center](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-5849).