CVE-2023-4762: Type Confusion in V8
Chromium: CVE-2023-4762 Type Confusion in V8
Other sources
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
— CISA
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 116.0.5845.179 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 116.0.1938.76 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 119.0.6045.199-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1 - Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4762?
CVE-2023-4762 is a vulnerability identified as Type Confusion in V8 in Google Chrome prior to 116.0.5845.179.
What is the severity of CVE-2023-4762?
CVE-2023-4762 has a severity rating of High (8.8) according to the Chromium security severity scale.
How does CVE-2023-4762 impact Microsoft Edge?
CVE-2023-4762 affects Microsoft Edge (Chromium-based) versions up to 116.0.1938.xxx.
How does CVE-2023-4762 impact Google Chrome?
CVE-2023-4762 affects Google Chrome versions up to 116.0.5845.179.
What is the remedy for CVE-2023-4762 on Debian Linux?
The remedy for CVE-2023-4762 on Debian Linux is to update the 'chromium' package to at least version 117.0.5938.62-1~deb11u1 for Debian 11, version 117.0.5938.62-1~deb12u1 for Debian 12, or version 117.0.5938.62-1 for Debian unstable.