CVE-2023-5186: Use after free in Passwords
Chromium: CVE-2023-5186 Use after free in Passwords
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)
Credit
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5186?
CVE-2023-5186 is a vulnerability in Google Chrome and Microsoft Edge that allows a remote attacker to potentially exploit heap corruption via crafted UI interaction.
How severe is CVE-2023-5186?
CVE-2023-5186 has a severity rating of High.
Which software versions are affected by CVE-2023-5186?
Google Chrome versions prior to 117.0.5938.132 and Microsoft Edge versions prior to 117.0.2045.47 are affected by CVE-2023-5186.
How do I fix CVE-2023-5186 in Google Chrome?
To fix CVE-2023-5186 in Google Chrome, update to version 117.0.5938.132 or later.
How do I fix CVE-2023-5186 in Microsoft Edge?
To fix CVE-2023-5186 in Microsoft Edge, update to version 117.0.2045.47 or later.