CERT-In Vulnerability Note
CIVN-2023-0075
Multiple Vulnerabilities in Google Chrome
Original Issue Date:March 14, 2023
Severity Rating: HIGH
Software Affected
- Google Chrome versions prior to 111.0.5563.64/.65 for Windows
- Google Chrome versions prior to 111.0.5563.64 for Mac and Linux.
Overview
Multiple Vulnerabilities have been reported in Google Chrome which could be exploited by a remote attacker to bypass security restriction, execute arbitrary code, gain access to sensitive information and cause denial of service condition on the targeted system.
Description
These vulnerabilities exist in Google Chrome for Desktop due to Heap buffer overflow in Metrics, UMA and Web Audio; Inappropriate implementation in Permission prompts, WebApp Installs, Autofill, Intents and Internals; Insufficient policy enforcement in Resource Timing ,Extensions API, Autofill, Web Payments API, Navigation and Intents; Stack buffer overflow in Crash reporting; Type Confusion in V8, CSS and DevTools; Use after free in Swiftshader, DevTools, WebRTC and Core. A remote attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted web page.
Successful exploitation of these vulnerabilities could allow a remote attacker to bypass security restriction, execute arbitrary code, gain access to sensitive information and cause denial of service condition on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.html
References
Google Chrome
https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.html
CVE Name
CVE-2023-1214
CVE-2023-1215
CVE-2023-1213
CVE-2023-1216
CVE-2023-1217
CVE-2023-1218
CVE-2023-1219
CVE-2023-1220
CVE-2023-1221
CVE-2023-1222
CVE-2023-1223
CVE-2023-1224
CVE-2023-1225
CVE-2023-1226
CVE-2023-1227
CVE-2023-1228
CVE-2023-1229
CVE-2023-1230
CVE-2023-1231
CVE-2023-1232
CVE-2023-1233
CVE-2023-1234
CVE-2023-1235
CVE-2023-1236
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|