CVE-2023-5855 is a use-after-free vulnerability in Google Chrome's Reading Mode, affecting versions prior to 119.0.6045.105, as well as various Debian and Fedora distributions. This high-severity flaw (CVSS 8.8) allows a remote attacker to potentially cause heap corruption and achieve high impact on confidentiality, integrity, and availability if a user is tricked into specific UI gestures. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 119.0.6045.105, < 119.0.6045.105CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 119.0.6045.105CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.