Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 147.0.7727.55 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cve_cpe | 95% |
| chrome | cert_advisory | 90% | |
| linux | linux_kernel | cve_cpe | 95% |
| microsoft | microsoft edge | cert_advisory | 90% |
| microsoft | windows | cve_cpe | 95% |
Updated vendor to Microsoft, added product Edge, marked exploit as available, and added new tag 'chromium'.
Updated severity to CRITICAL, added new affected version 146.0.7680.178, and changed exploit availability status.
Initial creation