Описание
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
A flaw was found in chromium-browser. This use-after-free vulnerability in the Views component allows a remote attacker to potentially exploit heap corruption. By convincing a user to engage in specific user interface gestures and visit a crafted HTML page, an attacker could achieve arbitrary code execution.
Отчет
This Important flaw in chromium-browser allows a remote attacker to achieve arbitrary code execution. The vulnerability, a use-after-free in the Views component, requires a user to visit a specially crafted HTML page and engage in specific user interface gestures, making it dependent on user interaction but still posing a significant risk due to the potential for full system compromise.
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
EPSS
7.5 High
CVSS3