HIGH
CVE-2023-4762
CVSS
8.8
KEV
Description
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
Type confusion vulnerability in Google Chrome's V8 JavaScript engine allows a remote attacker to execute arbitrary code via a crafted HTML page. The flaw exists in versions prior to 116.0.5845.179 and enables memory corruption that can be leveraged for code execution.
Mitigation
Update Google Chrome to version 116.0.5845.179 or later. In enterprise environments, deploy the update via patch management tooling or group policy.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
41.08%
Probability of exploitation in next 30 days
98.6th percentile
References
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html
Vendor Advisory
https://crbug.com/1473247
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/27NR3KG553CG6LGPMP6SHWEVHTYPL6RC/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/
Mailing List
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4762
Patch, Third Party Advisory
https://security.gentoo.org/glsa/202311-11
Third Party Advisory
https://security.gentoo.org/glsa/202312-07
Third Party Advisory
https://security.gentoo.org/glsa/202401-34
Third Party Advisory
https://www.debian.org/security/2023/dsa-5491
Mailing List, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4762
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.