CVE-2023-2933 is a high-severity use-after-free vulnerability in Google Chrome prior to version 114.0.5735.90, specifically affecting its PDF component. A remote attacker could exploit this by tricking a user into opening a crafted PDF file, leading to heap corruption and potential arbitrary code execution. With a CVSS score of 8.8, this vulnerability has a high impact on confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. While there is no evidence of active exploitation (KEV listed as No) and no public exploit code available, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 114.0.5735.90CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 114.0.5735.90, < 114.0.5735.90CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.