CVE-2023-6706: 114 is being updated in the LTS channel to 114.0.5735.347 (Platform Version: 15437.87.0) for most ChromeOS devices. Want to know more about Long Term Support? Click here.
Chromium: CVE-2023-6706 Use after free in FedCM
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6706?
CVE-2023-6706 is classified as a high severity vulnerability due to a use-after-free error in Chromium.
How do I fix CVE-2023-6706?
To mitigate CVE-2023-6706, users should update Google Chrome to version 120.0.6099.109 or higher, and similarly update Microsoft Edge to the latest version.
Which software is affected by CVE-2023-6706?
CVE-2023-6706 affects Google Chrome versions prior to 120.0.6099.109 and Microsoft Edge (Chromium-based) versions prior to 120.0.2210.77.
Is CVE-2023-6706 a remote vulnerability?
Yes, CVE-2023-6706 is considered a remote vulnerability that could potentially be exploited by an attacker.
What type of vulnerability is CVE-2023-6706?
CVE-2023-6706 is categorized as a use-after-free vulnerability, which can lead to arbitrary code execution.