CVE-2023-1227

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
07/03/2023
Last modified:
11/10/2024

Description

Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* 111.0.5563.64 (excluding)
cpe:2.3:o:google:linux_and_chrome_os:-:*:*:*:*:*:*:*