CVE-2023-5187: Use after free in Extensions
Chromium: CVE-2023-5187 Use after free in Extensions
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5187?
CVE-2023-5187 is a vulnerability in Extensions in Google Chrome and Microsoft Edge that allows an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
How severe is CVE-2023-5187?
CVE-2023-5187 has a severity rating of High, with a severity score of 8.8.
Which software versions are affected by CVE-2023-5187?
Google Chrome versions before 117.0.5938.132 and Microsoft Edge versions before 117.0.2045.47 are affected by CVE-2023-5187.
How can I fix CVE-2023-5187 in Google Chrome?
To fix CVE-2023-5187 in Google Chrome, update to version 117.0.5938.132 or later.
How can I fix CVE-2023-5187 in Microsoft Edge?
To fix CVE-2023-5187 in Microsoft Edge, update to version 117.0.2045.47 or later.