Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-23574
HistoryMar 23, 2023 - 12:00 a.m.

Google Chrome ANGLE out-of-bounds read vulnerability

2023-03-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
google chrome
angle
out-of-bounds read
vulnerability
heap corruption
web browser
remote attacker
user-supplied data
validation
crafted data
html page

EPSS

0.009

Percentile

82.8%

Google Chrome is a web browser from Google, Inc. An out-of-bounds read vulnerability exists in versions of Google Chrome prior to 111.0.5563.110, which stems from a lack of proper validation of user-supplied data by ANGLE, where specially crafted data could trigger a read beyond the end of the allocated buffer. A remote attacker could exploit the vulnerability to potentially exploit heap corruption via a carefully crafted HTML page.