CVE-2023-5854: Use after free in Profiles
Chromium: CVE-2023-5854 Use after free in Profiles
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-5854?
CVE-2023-5854 is a vulnerability labeled as 'Use after free in Profiles' in Google Chrome prior to version 119.0.6045.105.
What is the severity of CVE-2023-5854?
CVE-2023-5854 has a security severity rating of Medium.
How can an attacker exploit CVE-2023-5854?
A remote attacker can potentially exploit CVE-2023-5854 by convincing a user to engage in specific UI gestures to trigger a use-after-free vulnerability that may lead to heap corruption.
Which software versions are affected by CVE-2023-5854?
Microsoft Edge (Chromium-based) versions up to 119.0.2151.44 are affected by CVE-2023-5854.
How can I fix CVE-2023-5854?
Update Microsoft Edge (Chromium-based) to version 119.0.2151.44 or higher to mitigate the vulnerability.