Back to Labs
Security Advisory

CVE-2023-1220

About

Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Weakness (CWE):CWE-787

Rainforest analyst review

This is a heap buffer overflow in Chrome's UMA (metrics) component, but read the precondition carefully: it only helps an attacker who has already compromised the renderer process. From that already-elevated position, a crafted page can corrupt the heap and potentially push the compromise further. It is a link in a sandbox-escape chain, not an entry point.

That precondition changes how urgent this is. On its own it does nothing to a fresh target; it is valuable to sophisticated actors assembling a multi-bug exploit chain to break out of Chrome's sandbox, which is a very different threat profile from a broadly exploitable remote bug. High severity in isolation, but the 'renderer already compromised' gate keeps it out of commodity mass-exploitation.

For us this is a patch-cadence-and-trust-the-channel item: Chrome's auto-update carries the fix past 111.0.5563.64, and our job is confirming managed fleets aren't stuck behind policy on an older build. We would prioritize it above a purely cosmetic browser bug because chain components do get weaponized against high-value users, but the mitigation is the same routine update rather than anything bespoke.

References

Related CVEs

Frequently asked questions

What is CVE-2023-1220?

Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

How severe is CVE-2023-1220?

CVE-2023-1220 carries a CVSS 3.1 base score of 8.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 88 out of 100, in the critical band.

How is CVE-2023-1220 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction Required. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2023-1220?

Public advisories list the following as affected: chrome. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-1220?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email