CVE-2023-3737
https://notcve.org/view.php?id=CVE-2023-3737
20 Jul 2023 — Inappropriate implementation in Notifications in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to spoof the contents of media notifications via a crafted HTML page. (Chromium security severity: Medium) Una implementación inadecuada en Notificaciones en Google Chrome anterior a 115.0.5790.98 permitía a un atacante remoto falsificar el contenido de las notificaciones multimedia a través de una página HTML manipulada. (Gravedad de seguridad de Chromium: Media) • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-desktop.html •
CVE-2023-3738
https://notcve.org/view.php?id=CVE-2023-3738
20 Jul 2023 — Inappropriate implementation in Autofill in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-desktop.html •
CVE-2023-3740
https://notcve.org/view.php?id=CVE-2023-3740
20 Jul 2023 — Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low) La validación insuficiente de entradas no fiables en los Temas de Google Chrome anteriores a la versión 115.0.5790.98 permitía a un atacante remoto servir contenido malicioso a un usuario a través de una URL de fondo manipulada. (Gravedad de seguridad de Chromium: Baja) • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-desktop.html •
CVE-2023-3497
https://notcve.org/view.php?id=CVE-2023-3497
03 Jul 2023 — Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium) • https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-chromeos.html • CWE-125: Out-of-bounds Read •
CVE-2023-3422
https://notcve.org/view.php?id=CVE-2023-3422
26 Jun 2023 — Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html • CWE-416: Use After Free •
CVE-2023-3421
https://notcve.org/view.php?id=CVE-2023-3421
26 Jun 2023 — Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html • CWE-416: Use After Free •
CVE-2023-3420
https://notcve.org/view.php?id=CVE-2023-3420
26 Jun 2023 — Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2023-3217 – Chrome device::OpenXrApiWrapper::InitSession Heap Use-After-Free
https://notcve.org/view.php?id=CVE-2023-3217
13 Jun 2023 — Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Chrome suffers from a heap use-after-free vulnerability in device::OpenXrApiWrapper::InitSession. Versions affected include Google Chrome 114.0.5735.45 (Official Build) and Chromium 116.0.5806.0 (Developer Build). • http://packetstormsecurity.com/files/173495/Chrome-device-OpenXrApiWrapper-InitSession-Heap-Use-After-Free.html • CWE-416: Use After Free •
CVE-2023-3216
https://notcve.org/view.php?id=CVE-2023-3216
13 Jun 2023 — Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_13.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2023-3215
https://notcve.org/view.php?id=CVE-2023-3215
13 Jun 2023 — Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) • https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_13.html • CWE-416: Use After Free •