Rewterz
Rewterz Threat Alert – North Korean Threat Actors Evade Detection by Combining Malware Tactics – Active IOCs
November 29, 2023
Rewterz
Rewterz Threat Update – Ardent Health Services Faces Ransomware Crisis: 30 Hospitals Across Six States Disrupted
November 29, 2023

Rewterz Threat Advisory – Multiple Google Chrome Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-6351 CVSS:8.8

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in libavif. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.

CVE-2023-6350 CVSS:8.8

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds memory access in libavif. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.

CVE-2023-6346 CVSS:8.8

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in WebAudio. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.

CVE-2023-6348 CVSS:8.8

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a type of confusion in Spellcheck. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.

CVE-2023-6347 CVSS:8.8

Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in Mojo. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.

Impact

  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2023-6351
  • CVE-2023-6350
  • CVE-2023-6346
  • CVE-2023-6348
  • CVE-2023-6347

Affected Vendors

Google

Affected Products

  • Google Chrome 119.0

Remediation

Upgrade to the latest version of Google Chrome, available from the Google Chrome Releases Web site.

Google Chrome Releases Website