CVE-2023-6348 is a high-severity Type Confusion vulnerability in the Spellcheck component of Google Chrome prior to version 119.0.6045.199, affecting various Debian, Fedora, and Google Chrome distributions. A remote attacker could exploit this by compromising the renderer process through a crafted HTML page, potentially leading to heap corruption and significant impacts on confidentiality, integrity, and availability. While it has a high CVSS score of 8.8 and has garnered some community discussion and media coverage, there is currently no evidence of active exploitation, nor are there publicly available exploit tools like Metasploit or Nuclei modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 119.0.6045.199, < 119.0.6045.199CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 119.0.6045.199CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.