Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 147.0.7727.55 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| chrome | cert_advisory | 90% | |
| microsoft | microsoft edge | cert_advisory | 90% |
Updated severity to CRITICAL, added new affected version 146.0.7680.178, and changed exploit availability status.
Initial creation