Rewterz Threat Alert – North Korean Threat Actors Evade Detection by Combining Malware Tactics – Active IOCs
November 29, 2023Rewterz Threat Update – Ardent Health Services Faces Ransomware Crisis: 30 Hospitals Across Six States Disrupted
November 29, 2023Rewterz Threat Alert – North Korean Threat Actors Evade Detection by Combining Malware Tactics – Active IOCs
November 29, 2023Rewterz Threat Update – Ardent Health Services Faces Ransomware Crisis: 30 Hospitals Across Six States Disrupted
November 29, 2023Severity
High
Analysis Summary
CVE-2023-6351 CVSS:8.8
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in libavif. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.
CVE-2023-6350 CVSS:8.8
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds memory access in libavif. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.
CVE-2023-6346 CVSS:8.8
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in WebAudio. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.
CVE-2023-6348 CVSS:8.8
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a type of confusion in Spellcheck. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.
CVE-2023-6347 CVSS:8.8
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in Mojo. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.
Impact
- Code Execution
Indicators Of Compromise
CVE
- CVE-2023-6351
- CVE-2023-6350
- CVE-2023-6346
- CVE-2023-6348
- CVE-2023-6347
Affected Vendors
Affected Products
- Google Chrome 119.0
Remediation
Upgrade to the latest version of Google Chrome, available from the Google Chrome Releases Web site.