Executive brief
A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability has been observed being exploited in the wild.
Affected products
- Google Chrome prior to 112.0.5615.121
- Microsoft Edge
- Opera Software Opera
- Couchbase Couchbase Server up to (excluding) 7.1.5, 7.2.0
Timeline
- 2023-04-14: patched: Stable channel update for desktop released.
- 2023-04-17: disclosed: Vulnerability published and added to CISA KEV catalog.
- 2023-04-17: kev added
- 2023-04-17: exploited: Reported as exploited in the wild.