VDB
CVE-2023-2724
CVE-2023-2724
PUBLISHED
In Google Chrome und Microsoft Edge existieren mehrere Schwachstellen. Die Fehler bestehen aufgrund mehrerer Use-After-Free Fehler, einer Typverwechslung und einer unsachgemäßen Implementierung von WebApp-Installationen. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, indem er eine speziell gestaltete Webseite erstellt und das Opfer zum Besuch dieser Seite verleitet, um potenziell beliebigen Code auszuführen und andere, nicht näher spezifizierte Auswirkungen zu erreichen.
EPSS 10.42% · 93.4th percentile
Risk Scores
EPSS Score
10.42%
93.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | |
| Fedora | Fedora Linux | |
| IGEL | IGEL OS | |
| Gentoo | Gentoo Linux |
Exploit Intelligence
- https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_16.html (circl)
- https://crbug.com/1433211 (circl)
- https://www.debian.org/security/2023/dsa-5404 (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/73XUIHJ6UT75VFPDPLJOXJON7MVIKVZI/ (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FXFL4TDAH72PRCPD5UPZMJMKIMVOPLTI/ (circl)
- http://packetstormsecurity.com/files/173131/Chrome-Internal-JavaScript-Object-Access-Via-Origin-Trials.html (circl)
- https://security.gentoo.org/glsa/202309-17 (circl)
- https://security.gentoo.org/glsa/202311-11 (circl)
Timeline
- May 16, 2023 CVE Published
- May 17, 2023 EPSS Score
- Jul 29, 2023 EPSS Score
- Sep 4, 2023 EPSS Score
- Nov 16, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
- Mar 4, 2024 EPSS Score
- May 16, 2024 EPSS Score
- Jun 22, 2024 EPSS Score
- Sep 3, 2024 EPSS Score
- Nov 15, 2024 EPSS Score
- Dec 22, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1232.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1232 advisory
- https://security.gentoo.org/glsa/202311-11 advisory
- https://security.gentoo.org/glsa/202309-17 advisory
- https://kb.igel.com/securitysafety/en/isn-2023-08-chromium-critical-vulnerability-88026345.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-1388277bf4 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-6fba4b91e0 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-69264c19f9 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-5c477a04ca advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-2694488870 advisory
- https://www.debian.org/security/2023/dsa-5404 advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security advisory
- https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_16.html advisory