CVE-2023-6351: Use after free in libavif
Chromium: CVE-2023-6351 Use after free in libavif
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6351?
The severity of CVE-2023-6351 is High.
How does CVE-2023-6351 affect Microsoft Edge?
CVE-2023-6351 affects Microsoft Edge (Chromium-based) versions up to 119.0.2151.97.
How can a remote attacker exploit CVE-2023-6351?
A remote attacker can potentially exploit CVE-2023-6351 by using a crafted avif file to cause heap corruption.
Is there a fix available for CVE-2023-6351?
Yes, a fix is available for CVE-2023-6351. Update to Google Chrome version 119.0.6045.199 or later for the fix.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-6351?
The CWE ID for CVE-2023-6351 is 416.