CVE-2023-6702
33Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 44%
exploitation probability
44%top 1% of all CVEs
observed exploitation
nono source reports it
In short
A type confusion bug in Chrome's V8 engine allows attackers to send a specially crafted webpage that causes memory corruption, potentially letting them execute harmful code on your computer.
Technical detail
Type confusion vulnerability in V8 allows remote code execution through heap corruption. Attack vector: malicious HTML page delivered to victim; requires user interaction (page visit); impact includes arbitrary code execution with renderer process privileges.
Summary generated and translated by AI from the official description.
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · ChromeReferences
https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_12.htmlhttps://crbug.com/1501326https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6NWZ23ZJ62XKWVNGHSIZQYILVJWH5BLI/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZGJ732QHS2FAYF62RFF3YP4VIQY75K7V/https://security.gentoo.org/glsa/202401-34