CVE-2023-5187: Use after free in Extensions
Published Aug 25, 2023
·Updated
Chromium: CVE-2023-5187 Use after free in Extensions
Credit
Thomas Orlita
Affected Software
10 affected componentsFixes available
debian/chromium<=90.0.4430.212-1~deb10u1, <=116.0.5845.180-1~deb11u1
120.0.6099.129-1~deb11u1119.0.6045.199-1~deb12u1120.0.6099.129-1~deb12u1120.0.6099.129-1
Microsoft Edge (Chromium-based)
Microsoft Edge<117.0.2045.47
Google Chrome<117.0.5938.132
117.0.5938.132
Google Chrome<117.0.5938.132
Debian Debian Linux=11.0
Debian Debian Linux=12.0
fedoraproject fedora=37
fedoraproject fedora=38
fedoraproject fedora=39
Event History
Aug 25, 2023
CVE Published
12:00 AM
Sep 28, 2023
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-5187?
CVE-2023-5187 is a vulnerability in Extensions in Google Chrome and Microsoft Edge that allows an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
2
How severe is CVE-2023-5187?
CVE-2023-5187 has a severity rating of High, with a severity score of 8.8.
3
Which software versions are affected by CVE-2023-5187?
Google Chrome versions before 117.0.5938.132 and Microsoft Edge versions before 117.0.2045.47 are affected by CVE-2023-5187.
4
How can I fix CVE-2023-5187 in Google Chrome?
To fix CVE-2023-5187 in Google Chrome, update to version 117.0.5938.132 or later.
5
How can I fix CVE-2023-5187 in Microsoft Edge?
To fix CVE-2023-5187 in Microsoft Edge, update to version 117.0.2045.47 or later.