HIGH

CVE-2023-4762

Google Chrome 2023-09-05 CVSS v3.1
CVSS
8.8
KEV

Description

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

Type confusion vulnerability in Google Chrome's V8 JavaScript engine allows a remote attacker to execute arbitrary code via a crafted HTML page. The flaw exists in versions prior to 116.0.5845.179 and enables memory corruption that can be leveraged for code execution.

Mitigation

Update Google Chrome to version 116.0.5845.179 or later. In enterprise environments, deploy the update via patch management tooling or group policy.

Patch Commit

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

41.08%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE