Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:deb/debian/chrome

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Join the discussion
0

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Join the discussion
0

Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Join the discussion
0

CVE-2023-5997 is a use-after-free vulnerability in the garbage collection mechanism of Google Chrome versions prior to 119.0.6045.159. This flaw allows a remote attacker to trigger heap corruption by crafting a malicious HTML page, potentially leading to arbitrary code execution or browser compromise. Exploitation does not require user authentication but does require user interaction to visit a malicious webpage. No known exploits are currently in the wild. The vulnerability affects a widely used browser, making it a significant risk for European organizations relying on Chrome for web access. Timely patching is critical to prevent exploitation. The severity is assessed as high due to the potential impact on confidentiality, integrity, and availability, combined with the ease of exploitation via web content.

Join the discussion
0

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Join the discussion
0

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Join the discussion
0

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Join the discussion
0

CVE-2023-2136 is a critical integer overflow vulnerability in the Skia graphics library used by Google Chrome versions prior to 112.0.5615.137. This flaw allows a remote attacker who has already compromised the renderer process to potentially escape the browser's sandbox by crafting a malicious HTML page. The vulnerability impacts confidentiality, integrity, and availability with a high CVSS score of 9.6, indicating critical severity. Exploitation requires user interaction but no prior privileges or authentication. Although no known exploits are currently reported in the wild, the risk of sandbox escape makes this a significant threat. European organizations using vulnerable Chrome versions are at risk, especially those with high exposure to web-based threats.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:deb/debian/chrome
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses