CVE-2023-4362: Heap buffer overflow in Mojom IDL
Chromium: CVE-2023-4362 Heap buffer overflow in Mojom IDL
Other sources
Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-4369
- CVE-2023-20593
- CVE-2023-4211
- CVE-2023-4128
- CVE-2023-4147
- CVE-2023-3390
- CVE-2023-32804
- CVE-2022-40982
- CVE-2023-2312
- CVE-2023-4349
- CVE-2023-4350
- CVE-2023-4351
- CVE-2023-4352
- CVE-2023-4353
- CVE-2023-4354
- CVE-2023-4355
- CVE-2023-4356
- CVE-2023-4357
- CVE-2023-4358
- CVE-2023-4359
- CVE-2023-4360
- CVE-2023-4361
- CVE-2023-4363
- CVE-2023-4364
- CVE-2023-4365
- CVE-2023-4366
- CVE-2023-4367
- CVE-2023-4368
- CVE-2023-21264
- CVE-2020-29374
Frequently Asked Questions
What is the severity of CVE-2023-4362?
The severity of CVE-2023-4362 is medium.
How can a remote attacker exploit CVE-2023-4362?
A remote attacker can potentially exploit CVE-2023-4362 by compromising the renderer process and gaining control of a WebUI process, then using a crafted HTML page to exploit heap corruption.
Which software is affected by CVE-2023-4362?
Microsoft Edge (Chromium-based), Microsoft Edge version 116.0.1938.54, Google Chrome version up to 116.0.5845.96, Debian Debian Linux version 11.0 and version 12.0, and Debian Chromium packages with versions up to 114.0.5735.198-1~deb12u1 are affected by CVE-2023-4362.
How can I fix CVE-2023-4362?
To fix CVE-2023-4362, update to Microsoft Edge version 116.0.1938.54 or later, Google Chrome version 116.0.5845.96 or later, or the latest available version of Debian Chromium packages.
Are there any references for CVE-2023-4362?
Yes, you can find references for CVE-2023-4362 at the following links: [MSRC Microsoft](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4362), [Google Chrome Releases](https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop_15.html), and [Chromium Bug Tracker](https://crbug.com/1316379).