Описание
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
A flaw was found in Google Chrome Extensions. This use-after-free vulnerability allows a remote attacker to execute arbitrary code within the browser's sandbox. Exploitation occurs when a user is convinced to install a specially crafted malicious extension.
Отчет
This Important flaw in Google Chrome Extensions allows for arbitrary code execution within the browser's sandbox. Exploitation requires a user to be convinced to install a malicious extension, limiting the attack vector to user interaction rather than remote, unauthenticated access.
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 ...
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
7.3 High
CVSS3