CVE-2023-6703: Use after free in Blink
Chromium: CVE-2023-6703 Use after free in Blink
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6703?
CVE-2023-6703 is rated as a high severity vulnerability due to the potential for exploitation through a use-after-free condition.
How do I fix CVE-2023-6703?
To fix CVE-2023-6703, users should update their Google Chrome to version 120.0.6099.109 or later or Microsoft Edge to the latest version that contains the Chromium updates.
What versions of Chromium are affected by CVE-2023-6703?
CVE-2023-6703 affects versions of Google Chrome up to 120.0.6099.109 and Microsoft Edge up to 120.0.2210.77.
Is CVE-2023-6703 specific to any particular operating system?
CVE-2023-6703 is not specific to any operating system as it affects applications built on the Chromium engine, including Google Chrome and Microsoft Edge.
Can CVE-2023-6703 be exploited remotely?
Yes, CVE-2023-6703 can be exploited remotely, allowing attackers to execute arbitrary code through specially crafted web content.