HIGH

CVE-2023-2033

Google Chrome 2023-04-14 CVSS v3.1
CVSS
8.8
KEV

Description

Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

This is a type confusion vulnerability in Google Chrome's V8 JavaScript engine. Type confusion occurs when the JavaScript engine incorrectly handles objects of different types, allowing an attacker to manipulate memory and cause heap corruption. The vulnerability can be triggered remotely via a specially crafted HTML page.

Mitigation

Update Google Chrome to version 112.0.5615.121 or later. In enterprise environments, use software deployment tools or group policy to ensure consistent browser updates across all clients.

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

40.8%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE