CVE-2023-5186: Use after free in Passwords
Published Sep 5, 2023
·Updated
Chromium: CVE-2023-5186 Use after free in Passwords
Credit
[pwn2car]
Affected Software
10 affected componentsFixes available
debian/chromium<=90.0.4430.212-1~deb10u1, <=116.0.5845.180-1~deb11u1
120.0.6099.129-1~deb11u1119.0.6045.199-1~deb12u1120.0.6099.129-1~deb12u1120.0.6099.129-1
Microsoft Edge (Chromium-based)
Microsoft Edge<117.0.2045.47
Google Chrome<117.0.5938.132
117.0.5938.132
Google Chrome<117.0.5938.132
Debian Debian Linux=11.0
Debian Debian Linux=12.0
fedoraproject fedora=37
fedoraproject fedora=38
fedoraproject fedora=39
Event History
Sep 5, 2023
CVE Published
12:00 AM
Sep 28, 2023
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-5186?
CVE-2023-5186 is a vulnerability in Google Chrome and Microsoft Edge that allows a remote attacker to potentially exploit heap corruption via crafted UI interaction.
2
How severe is CVE-2023-5186?
CVE-2023-5186 has a severity rating of High.
3
Which software versions are affected by CVE-2023-5186?
Google Chrome versions prior to 117.0.5938.132 and Microsoft Edge versions prior to 117.0.2045.47 are affected by CVE-2023-5186.
4
How do I fix CVE-2023-5186 in Google Chrome?
To fix CVE-2023-5186 in Google Chrome, update to version 117.0.5938.132 or later.
5
How do I fix CVE-2023-5186 in Microsoft Edge?
To fix CVE-2023-5186 in Microsoft Edge, update to version 117.0.2045.47 or later.