HIGH
CVE-2023-2033
CVSS
8.8
KEV
Description
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
This is a type confusion vulnerability in Google Chrome's V8 JavaScript engine. Type confusion occurs when the JavaScript engine incorrectly handles objects of different types, allowing an attacker to manipulate memory and cause heap corruption. The vulnerability can be triggered remotely via a specially crafted HTML page.
Mitigation
Update Google Chrome to version 112.0.5615.121 or later. In enterprise environments, use software deployment tools or group policy to ensure consistent browser updates across all clients.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
40.8%
Probability of exploitation in next 30 days
98.6th percentile
References
https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html
Release Notes, Vendor Advisory
https://crbug.com/1432210
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4AOSGAOPXLBK4A5ZRTVZ4M6QKVLSWMWG/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ES2CDRHR2Y4WY6DNDIAPYZFXJU3ZBFAV/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FEJZMAUB4XP44HSHEBDWEKFGA7DUHY42/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IHHD6KNH4WLUE6JG6HRQZWNAJMHJ32X7/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJQI63HWZFL6M26Q6UOHKDY6LD2PFC5Z/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SLO7BL2MHZYPY6O3OAEAQL3SKYMGGO6M/
Mailing List
https://security.gentoo.org/glsa/202309-17
Third Party Advisory
https://www.couchbase.com/alerts/
Third Party Advisory
https://www.debian.org/security/2023/dsa-5390
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-2033
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.