High severity8.1NVD Advisory· Published Sep 5, 2023· Updated Jun 17, 2026
CVE-2023-4761
CVE-2023-4761
Description
Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
- osv-coords5 versionspkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweedpkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP4pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP5pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.5
< 116.0.5845.179-1.1+ 4 more
- (no CPE)range: < 116.0.5845.179-1.1
- (no CPE)range: < 116.0.5845.179-bp155.2.28.1
- (no CPE)range: < 116.0.5845.179-bp155.2.28.1
- (no CPE)range: < 116.0.5845.179-bp155.2.28.1
- (no CPE)range: < 116.0.5845.179-bp155.2.28.1
Patches
Vulnerability mechanics
References
9- chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.htmlnvdRelease NotesVendor Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/27NR3KG553CG6LGPMP6SHWEVHTYPL6RC/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/nvdMailing ListThird Party Advisory
- www.debian.org/security/2023/dsa-5491nvdThird Party Advisory
- crbug.com/1476403nvdPermissions Required
- security.gentoo.org/glsa/202311-11nvd
- security.gentoo.org/glsa/202312-07nvd
- security.gentoo.org/glsa/202401-34nvd
News mentions
0No linked articles in our index yet.