Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page
Published Apr 4, 2023
8.8
HIGHCVSS 3.1
EPSS 0.91%
Description
Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Affected products
-
- Version 112.0.5615.49StatusaffectedConstraints<112.0.5615.49
- Version
Configuration 2
- 36
- 37
Configuration 3
- 11.0
-
- Version 0StatusaffectedConstraints<112.0.5615.49
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 8, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.91% (0.00914) | 58.66th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.91% (0.00914) | 55.26th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.66% (0.00656) | 70.23th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.41% (0.02410) | 83.76th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.70% (0.00696) | 69.60th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.24% (0.02242) | 74.21th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.73% (0.00732) | 71.04th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.56% (0.00563) | 78.49th | v3 (v2023.03.01) |
| Jul 9, 2024 | 0.36% (0.00360) | 72.43th | v3 (v2023.03.01) |
| May 6, 2024 | 0.32% (0.00324) | 70.57th | v3 (v2023.03.01) |
| Apr 10, 2024 | 0.27% (0.00273) | 67.56th | v3 (v2023.03.01) |
| Mar 16, 2024 | 0.17% (0.00170) | 53.01th | v3 (v2023.03.01) |
| Mar 4, 2024 | 0.18% (0.00181) | 54.57th | v3 (v2023.03.01) |
| Oct 25, 2023 | 0.18% (0.00175) | 54.43th | v3 (v2023.03.01) |
| Oct 1, 2023 | 0.22% (0.00222) | 60.08th | v3 (v2023.03.01) |
| Apr 15, 2023 | 0.13% (0.00127) | 45.95th | v3 (v2023.03.01) |
| Apr 12, 2023 | 0.08% (0.00082) | 33.32th | v3 (v2023.03.01) |
| Apr 10, 2023 | 0.06% (0.00055) | 20.91th | v3 (v2023.03.01) |
| Apr 5, 2023 | 0.05% (0.00047) | 14.18th | v3 (v2023.03.01) |
References (6)
- https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.html Release NotesVendor Advisory
- https://crbug.com/1278708 Issue TrackingPermissions RequiredThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FG3CRADL7IL5IHK4NCHG4LAYLKHFXETX/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HO3QZY4UQFP4XNF43ILMVVOABMB7KAQ5/ Mailing List
- https://security.gentoo.org/glsa/202309-17 Third Party Advisory
- https://www.debian.org/security/2023/dsa-5386 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.html | Release NotesVendor Advisory | |
| https://crbug.com/1278708 | Issue TrackingPermissions RequiredThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FG3CRADL7IL5IHK4NCHG4LAYLKHFXETX/ | Mailing List | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HO3QZY4UQFP4XNF43ILMVVOABMB7KAQ5/ | Mailing List | |
| https://security.gentoo.org/glsa/202309-17 | Third Party Advisory | |
| https://www.debian.org/security/2023/dsa-5386 | Third Party Advisory |
Change history (0)
No recorded changes yet.