CVE-2023-6704: Use after free in libavif
Chromium: CVE-2023-6704 Use after free in libavif
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted image file. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6704?
CVE-2023-6704 has a high severity rating due to its use-after-free nature that can be exploited for arbitrary code execution.
How do I fix CVE-2023-6704?
To fix CVE-2023-6704, update Google Chrome to version 120.0.6099.109 or Microsoft Edge to the latest version.
Which versions of Chromium are affected by CVE-2023-6704?
CVE-2023-6704 affects Chromium versions prior to 120.0.6099.109.
Can CVE-2023-6704 impact Microsoft Edge?
Yes, CVE-2023-6704 can impact Microsoft Edge (Chromium-based) versions below 120.0.2210.77.
Is there a workaround for CVE-2023-6704?
There are no recommended workarounds for CVE-2023-6704; the best solution is to apply the relevant software updates.