CVE-2023-5186 is a high-severity use-after-free vulnerability in Google Chrome's password management component, affecting versions prior to 117.0.5938.132, as well as various Debian and Fedora distributions. This flaw allows a remote attacker to potentially exploit heap corruption by convincing a user to engage in specific UI interactions. With a CVSS score of 8.8, the vulnerability has a network attack vector, low attack complexity, and can lead to high impacts on confidentiality, integrity, and availability. While no public exploit code is available, the vulnerability has garnered significant community discussion and media coverage, including reports of it being exploited in the wild by spyware vendors as a zero-day.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 117.0.5938.132, < 117.0.5938.132CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 117.0.5938.132CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.