CVE-2023-4068 is a high-severity type confusion vulnerability in the V8 JavaScript engine of Google Chrome, affecting versions prior to 115.0.5790.170. A remote attacker could exploit this flaw via a crafted HTML page to achieve arbitrary read/write capabilities. With a CVSS score of 8.1, exploitation requires user interaction (UI:R) but has low attack complexity (AC:L) and no authentication (PR:N), leading to high confidentiality and integrity impacts (C:H/I:H). While not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, with Google awarding bounties for its discovery, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 115.0.5790.170, < 115.0.5790.170CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 115.0.5790.170CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.