CVE-2023-2134: Out of bounds memory access in Service Worker API
Chromium: CVE-2023-2134 Out of bounds memory access in Service Worker API
Other sources
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-2134?
CVE-2023-2134 is a vulnerability that involves out of bounds memory access in the Service Worker API in Google Chrome.
What is the severity of CVE-2023-2134?
The severity of CVE-2023-2134 is high, with a severity value of 8.8.
How does CVE-2023-2134 impact Microsoft Edge (Chromium-based)?
Microsoft Edge (Chromium-based) is affected by CVE-2023-2134 and users should update to version 112.0.5615.137 or later to mitigate the vulnerability.
How does CVE-2023-2134 impact Google Chrome?
Google Chrome versions prior to 112.0.5615.137 are affected by CVE-2023-2134 and users should update to the latest version to address the vulnerability.
What is the remedy for CVE-2023-2134 in Debian Debian Linux?
Debian Debian Linux users should apply the remedy versions 116.0.5845.180-1~deb11u1, 119.0.6045.123-1~deb11u1, 116.0.5845.180-1~deb12u1, 119.0.6045.123-1~deb12u1, 119.0.6045.105-1, or 119.0.6045.123-1 of the Chromium package to fix CVE-2023-2134.