Vulnerability CVE-2023-2722: Information

Description

Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: May 16, 2023
Modified: Nov. 25, 2023
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
yandex-browser-stablesisyphus23.7.1.1216-alt124.1.3.845-alt1ALT-PU-2023-4763-2326697Fixed
yandex-browser-stablep1023.7.1.1216-alt124.1.3.845-alt1ALT-PU-2023-4767-2326709Fixed
yandex-browser-stablec10f123.7.1.1216-alt124.1.3.845-alt1ALT-PU-2023-4766-2326708Fixed
yandex-browser-stablec9f223.9.1.1033-alt124.1.3.845-alt1ALT-PU-2023-6351-2331674Fixed
yandex-browser-stablep1123.7.1.1216-alt124.1.3.845-alt1ALT-PU-2023-4763-2326697Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*