Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-6350

Description

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

POC

Reference

No PoCs from references.

Github

- https://github.com/dywsy21/CVE-2023-6350_Reproduction

- https://github.com/fdu-sec/NestFuzz

- https://github.com/lysgoup/NestFuzz_test

- https://github.com/nomi-sec/PoC-in-GitHub