CVE-2023-4069
https://notcve.org/view.php?id=CVE-2023-4069
03 Aug 2023 — Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2023-4068
https://notcve.org/view.php?id=CVE-2023-4068
03 Aug 2023 — Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2023-3739
https://notcve.org/view.php?id=CVE-2023-3739
01 Aug 2023 — Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low) La validación insuficiente de entradas no fiables en Chromad en Google Chrome en ChromeOS anterior a 115.0.5790.131 permitía a un atacante remoto ejecutar código arbitrario a través de un script de shell diseñado. (Gravedad de seguridad de Chromium: Baja) • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-chromeos.html • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-3731
https://notcve.org/view.php?id=CVE-2023-3731
01 Aug 2023 — Use after free in Diagnostics in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) user-after-free en Diagnósticos en Google Chrome en ChromeOS anterior a 115.0.5790.131 permitía a un atacante, que convenció a un usuario para instalar una extensión maliciosa, explotar potencialmente la corrupción del montículo a través de una exte... • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-chromeos.html • CWE-416: Use After Free •
CVE-2023-3729
https://notcve.org/view.php?id=CVE-2023-3729
01 Aug 2023 — Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium security severity: High) Vulnerabilidad de use-after-free en Splitscreen en Google Chrome en ChromeOS antes de 115.0.5790.131 permitió a un atacante remoto que convenció a un usuario a participar en interacciones específicas de interfaz de usuario para explotar pote... • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-chromeos.html • CWE-416: Use After Free •
CVE-2023-2314
https://notcve.org/view.php?id=CVE-2023-2314
28 Jul 2023 — Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) • https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.html • CWE-345: Insufficient Verification of Data Authenticity •
CVE-2023-2313
https://notcve.org/view.php?id=CVE-2023-2313
28 Jul 2023 — Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.html •
CVE-2023-2311
https://notcve.org/view.php?id=CVE-2023-2311
28 Jul 2023 — Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.html •
CVE-2022-4926
https://notcve.org/view.php?id=CVE-2022-4926
28 Jul 2023 — Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2023/01/stable-channel-update-for-desktop_24.html • CWE-522: Insufficiently Protected Credentials •
CVE-2021-4324
https://notcve.org/view.php?id=CVE-2021-4324
28 Jul 2023 — Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to read arbitrary files via a malicious file. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_26.html •