CVE-2023-4070 is a high-severity Type Confusion vulnerability in Google Chrome's V8 JavaScript engine, affecting versions prior to 115.0.5790.170. A remote attacker can exploit this flaw via a crafted HTML page to achieve arbitrary read/write capabilities. The vulnerability has a CVSS score of 8.1 (High), indicating a network-based attack with low complexity, requiring user interaction, and leading to high confidentiality and integrity impacts. While not currently listed in CISA's KEV catalog or having public exploit code, it has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 115.0.5790.170, < 115.0.5790.170CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 115.0.5790.170CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.