CVE-2023-3422 is a high-severity use-after-free vulnerability in Google Chrome, affecting versions prior to 114.0.5735.198, as well as Debian-based Chrome installations. An attacker could exploit this by convincing a user to install a malicious extension, leading to heap corruption via a crafted HTML page. With a CVSS score of 8.8, this vulnerability has a high impact on confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. There is currently no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code, though it has garnered some media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 114.0.5735.198CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
>= 114.0.5735.198, < 114.0.5735.198CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.