Описание
Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
chromium | fixed | 139.0.7258.127-1 | package | |
chromium | end-of-life | bullseye | package |
EPSS
Процентиль: 29%
0.00101
Низкий
Связанные уязвимости
CVSS3: 8.8
nvd
12 дней назад
Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVSS3: 8.8
github
12 дней назад
Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
EPSS
Процентиль: 29%
0.00101
Низкий