Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted UI interaction. (Chromium security severity: Low)
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/anthonyharrison/lib4sbom
- https://github.com/dhalubiec/baw-project
- https://github.com/espressif/esp-idf-sbom
- https://github.com/vonsteer/ecr-scan-action