CVE-2023-5852 is a use-after-free vulnerability in Google Chrome's printing component (prior to version 119.0.6045.105), affecting various Chrome and Debian/Fedora distributions. It carries a high CVSS score of 8.8, indicating a critical risk where a remote attacker could exploit heap corruption through specific user interface gestures, leading to high impacts on confidentiality, integrity, and availability. While no active exploitation or public exploit code is currently known, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 119.0.6045.105, < 119.0.6045.105CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 119.0.6045.105CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.