CVE-2023-5474

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 11, 2023
Updated: Jan 31, 2024
CWE ID 787

Summary

CVE-2023-5474 is a heap buffer overflow vulnerability affecting Google Chrome versions prior to 118.0.5993.70. This issue is located in the PDF handling component of the browser. An attacker could potentially exploit this vulnerability by crafting a PDF file and convincing a user to interact with it in a specific way. Successful exploitation could result in heap corruption, allowing the attacker to execute arbitrary code or cause other unintended behavior. The Chromium security team has rated this vulnerability as medium severity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share