CVE-2023-2133: Out of bounds memory access in Service Worker API
Chromium: CVE-2023-2133 Out of bounds memory access in Service Worker API
Other sources
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-2133?
The severity of CVE-2023-2133 is High.
How can a remote attacker exploit CVE-2023-2133?
A remote attacker can potentially exploit CVE-2023-2133 by using a crafted HTML page to exploit heap corruption in the Service Worker API.
Which software is affected by CVE-2023-2133?
The following software is affected by CVE-2023-2133: Google Chrome prior to 112.0.5615.137, Microsoft Edge (Chromium-based), Microsoft Edge version 112.0.1722.58, Debian Debian Linux version 11.0, Fedoraproject Fedora versions 36, 37, and 38.
Is there a fix available for CVE-2023-2133?
Yes, the fix for CVE-2023-2133 is available in Google Chrome version 112.0.5615.137.
Where can I find more information about CVE-2023-2133?
You can find more information about CVE-2023-2133 at the following references: [1](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-2133), [2](https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html), [3](https://crbug.com/1429197).