Use-after-free in Microsoft Edge - CVE-2023-29350
Published: May 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when handling HTML content. A remote attacker can trick the victim to visit a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Gentoo Linux
www-client/microsoft-edge
www-client/chromium
www-client/chromium-bin
www-client/google-chrome
How to mitigate CVE-2023-29350
www-client/microsoft-edge - update to 113.0.1774.50
www-client/chromium - update to 113.0.5672.126
www-client/chromium-bin - update to 113.0.5672.126
www-client/google-chrome - update to 113.0.5672.126