CVE-2022-4955
https://notcve.org/view.php?id=CVE-2022-4955
04 Aug 2023 — Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html •
CVE-2023-4078
https://notcve.org/view.php?id=CVE-2023-4078
03 Aug 2023 — Inappropriate implementation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html •
CVE-2023-4077
https://notcve.org/view.php?id=CVE-2023-4077
03 Aug 2023 — Insufficient data validation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html •
CVE-2023-4076
https://notcve.org/view.php?id=CVE-2023-4076
03 Aug 2023 — Use after free in WebRTC in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC session. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html • CWE-416: Use After Free •
CVE-2023-4075
https://notcve.org/view.php?id=CVE-2023-4075
03 Aug 2023 — Use after free in Cast in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html • CWE-416: Use After Free •
CVE-2023-4074
https://notcve.org/view.php?id=CVE-2023-4074
03 Aug 2023 — Use after free in Blink Task Scheduling in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html • CWE-416: Use After Free •
CVE-2023-4073
https://notcve.org/view.php?id=CVE-2023-4073
03 Aug 2023 — Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2023-4072
https://notcve.org/view.php?id=CVE-2023-4072
03 Aug 2023 — Out of bounds read and write in WebGL in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html • CWE-125: Out-of-bounds Read CWE-787: Out-of-bounds Write •
CVE-2023-4071
https://notcve.org/view.php?id=CVE-2023-4071
03 Aug 2023 — Heap buffer overflow in Visuals in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html • CWE-787: Out-of-bounds Write •
CVE-2023-4070
https://notcve.org/view.php?id=CVE-2023-4070
03 Aug 2023 — Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •