CVE-2023-4355: Out of bounds memory access in V8
Chromium: CVE-2023-4355 Out of bounds memory access in V8
Other sources
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-4369
- CVE-2023-20593
- CVE-2023-4211
- CVE-2023-4128
- CVE-2023-4147
- CVE-2023-3390
- CVE-2023-32804
- CVE-2022-40982
- CVE-2023-2312
- CVE-2023-4349
- CVE-2023-4350
- CVE-2023-4351
- CVE-2023-4352
- CVE-2023-4353
- CVE-2023-4354
- CVE-2023-4356
- CVE-2023-4357
- CVE-2023-4358
- CVE-2023-4359
- CVE-2023-4360
- CVE-2023-4361
- CVE-2023-4362
- CVE-2023-4363
- CVE-2023-4364
- CVE-2023-4365
- CVE-2023-4366
- CVE-2023-4367
- CVE-2023-4368
- CVE-2023-21264
- CVE-2020-29374
Frequently Asked Questions
What is the severity of CVE-2023-4355?
The severity of CVE-2023-4355 is High (8.8).
How does CVE-2023-4355 impact Microsoft Edge (Chromium-based)?
CVE-2023-4355 may allow a remote attacker to potentially exploit heap corruption via a crafted HTML page in Microsoft Edge (Chromium-based) versions prior to 116.0.5845.96.
Is Google Chrome affected by CVE-2023-4355?
Yes, Google Chrome versions prior to 116.0.5845.96 are affected by CVE-2023-4355.
How can I fix CVE-2023-4355 on Debian Debian Linux?
You can fix CVE-2023-4355 on Debian Debian Linux by updating to chromium version 117.0.5938.62-1~deb11u1 or 117.0.5938.62-1~deb12u1, depending on your Debian version.
Where can I find more information about CVE-2023-4355?
You can find more information about CVE-2023-4355 in the Microsoft Security Response Center (MSRC) update guide, the Google Chrome Releases blog, and the Chromium bug tracker.