Description: | Summary: Google Chrome is prone to multiple vulnerabilities.
Vulnerability Insight: Multiple flaws exist due to,
- Use after free in Swiftshader.
- Type Confusion in V8.
- Type Confusion in CSS.
- Use after free in DevTools.
- Stack buffer overflow in Crash reporting.
- Use after free in WebRTC.
- Heap buffer overflow in Metrics.
- Heap buffer overflow in UMA.
- Insufficient policy enforcement in Extensions API.
- Heap buffer overflow in Web Audio API.
- Insufficient policy enforcement in Autofill.
- Insufficient policy enforcement in Web Payments API.
- Insufficient policy enforcement in Navigation.
- Use after free in Core.
- Insufficient policy enforcement in Intents.
- Inappropriate implementation in Permission prompts.
- Inappropriate implementation in WebApp Installs.
- Inappropriate implementation in Autofill.
- Insufficient policy enforcement in Resource Timing.
- Inappropriate implementation in Intents.
- Type Confusion in DevTools.
- Inappropriate implementation in Internals.
Vulnerability Impact: Successful exploitation will allow attackers to run arbitrary code, bypass security restrictions, conduct spoofing and cause a denial of service on affected system.
Affected Software/OS: Google Chrome version prior to 111.0.5563.64 on Windows
Solution: Upgrade to Google Chrome version 111.0.5563.64 or later. Please see the references for more information.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|