Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 149.0.7827.103 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cve_cpe | 95% |
| chrome | cert_advisory | 90% | |
| linux | linux_kernel | cve_cpe | 95% |
| microsoft | windows | cve_cpe | 95% |
Loading…
Updated vendor to Microsoft and added product Edge, along with a new tag 'chromium-based'.
Added affected version 149.0.7827.102 for Linux and updated patch availability to null.
Added affected version 149.0.7827.102, updated severity to MEDIUM, and added new tags for multiple vulnerabilities.
Updated description with more technical detail, added CWE-125, and included new tags related to zero-day and high-severity.
Updated affected versions to include 149.0.7827.102, changed severity to CRITICAL, and added new tags related to security and exploit.
Updated description with more technical detail, marked as actively exploited, and noted that a patch is available.
Initial creation