CVE-2023-5472 is a high-severity use-after-free vulnerability in Google Chrome, affecting versions prior to 118.0.5993.117, as well as various Debian and Fedora distributions. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8, successful exploitation could lead to high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV list), public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 118.0.5993.117, < 118.0.5993.117CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 118.0.5993.117CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.