CVE-2026-2313

Description

Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.064

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Google Chrome (145.0.7632.45,145.0.7632.46)Windows
Multiple vulnerabilities are fixed in Google Chrome (x64) (145.0.7632.45,145.0.7632.46)Windows
Multiple vulnerabilities are fixed in Google Chrome (User Based) 145.0.7632.46Windows
Multiple vulnerabilities are fixed in Microsoft Edge for chromium business (145.0.3800.58) (x86)Windows
Multiple vulnerabilities are fixed in Microsoft Edge for chromium business (145.0.3800.58) (x64)Windows
Multiple vulnerabilities are fixed in Google Chrome for Mac (145.0.7632.45,145.0.7632.46)Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-355903Google Chrome (145.0.7632.45,145.0.7632.46)
PATCH-355904Google Chrome (x64) (145.0.7632.45,145.0.7632.46)
PATCH-613551Google Chrome for Mac (145.0.7632.45,145.0.7632.46)
PATCH-113034Microsoft Edge for chromium business (145.0.3800.65) (x86)
PATCH-113035Microsoft Edge for chromium business (145.0.3800.65) (x64)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234