Описание
Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
A flaw was found in Google Chrome. A remote attacker could exploit a use-after-free vulnerability in the PrivateAI component by convincing a user to engage in specific user interface (UI) gestures through a crafted HTML page. This could potentially allow the attacker to bypass the browser's security sandbox, leading to unauthorized access or control over the system.
Отчет
Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Дополнительная информация
Статус:
EPSS
9.6 Critical
CVSS3
Связанные уязвимости
Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 al ...
Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
EPSS
9.6 Critical
CVSS3