
CVE-2023-3730 – Debian Security Advisory 5456-1
https://notcve.org/view.php?id=CVE-2023-3730
20 Jul 2023 — Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) El use-after-free en Grupos de Pestañas en Google Chrome antes de 115.0.5790.98 permitió a un atacante remoto que convenció a un usuario a participar en interacciones específicas de interfaz de usuario para explotar potencialmente la corrupción del montículo ... • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-desktop.html • CWE-416: Use After Free •

CVE-2023-3732 – Chrome IPCZ FragmentDescriptors Missing Validation
https://notcve.org/view.php?id=CVE-2023-3732
20 Jul 2023 — Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Un acceso a memoria fuera de los límites en Mojo en Google Chrome anterior a la versión 115.0.5790.98 permitía a un atacante remoto que hubiera comprometido el proceso de renderizado explotar potencialmente la corrupción del montículo a través de una página HTML manipul... • https://packetstorm.news/files/id/174223 • CWE-787: Out-of-bounds Write •

CVE-2023-3733 – Debian Security Advisory 5456-1
https://notcve.org/view.php?id=CVE-2023-3733
20 Jul 2023 — Inappropriate implementation in WebApp Installs in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) La implementación inadecuada en WebApp Installs en Google Chrome anteriores a la versión 115.0.5790.98 permitía a un atacante remoto falsificar potencialmente el contenido de la Omnibox (barra de URL) a través de una página HTML manipulada. (Gravedad de seguridad de Chromium: ... • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-desktop.html •

CVE-2023-3734 – Debian Security Advisory 5456-1
https://notcve.org/view.php?id=CVE-2023-3734
20 Jul 2023 — Inappropriate implementation in Picture In Picture in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) La implementación inadecuada de Picture In Picture en Google Chrome anterior a la versión 115.0.5790.98 permitía a un atacante remoto falsificar potencialmente el contenido de la Omnibox (barra de URL) a través de una página HTML manipulada. (Gravedad de seguridad de Chromi... • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-desktop.html •

CVE-2023-3497
https://notcve.org/view.php?id=CVE-2023-3497
03 Jul 2023 — Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-chromeos.html • CWE-125: Out-of-bounds Read •

CVE-2023-3422 – Debian Security Advisory 5440-1
https://notcve.org/view.php?id=CVE-2023-3422
26 Jun 2023 — Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html • CWE-416: Use After Free •

CVE-2023-3421 – Debian Security Advisory 5440-1
https://notcve.org/view.php?id=CVE-2023-3421
26 Jun 2023 — Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html • CWE-416: Use After Free •

CVE-2023-3420 – Debian Security Advisory 5440-1
https://notcve.org/view.php?id=CVE-2023-3420
26 Jun 2023 — Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2023-3217 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-3217
13 Jun 2023 — Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Chrome suffers from a heap use-after-free vulnerability in device::OpenXrApiWrapper::InitSession. Versions affected include Google Chrome 114.0.5735.45 (Official Build) and Chromium 116.0.5806.0 (Developer Build). • https://packetstorm.news/files/id/173495 • CWE-416: Use After Free •

CVE-2023-3216 – Gentoo Linux Security Advisory 202311-11
https://notcve.org/view.php?id=CVE-2023-3216
13 Jun 2023 — Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Versions greater than or equal to 120.0.6099.109 are affected. • https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_13.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •