Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 147.0.7727.138 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cve_cpe | 95% |
| linux | linux_kernel | cve_cpe | 95% |
| microsoft | windows | cve_cpe | 95% |
Updated vendor to Microsoft, added product Edge, and marked exploit availability and active exploitation as true.
Added affected version 147.0.7727.137 and marked the vulnerability as actively exploited with an exploit available.
Updated affected versions to include 147.0.7727.117, changed severity to CRITICAL, and confirmed no exploit is available.
Initial creation