Описание
A flaw was found in Google Chrome. This use-after-free vulnerability in the Extensions component allows a remote attacker to execute arbitrary code within a sandbox. This can be exploited by convincing a user to install a specially crafted Chrome Extension.
Отчет
This Important flaw in Google Chrome's Extensions component allows arbitrary code execution within the browser's sandbox. While user interaction is required to install a specially crafted Chrome Extension, the ability to execute code within the sandbox represents a significant security risk to the system.
Дополнительная информация
Статус:
EPSS
7.6 High
CVSS3
Связанные уязвимости
Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
Use after free in Extensions in Google Chrome prior to 151.0.7922.72 a ...
Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
EPSS
7.6 High
CVSS3