### [CVE-2023-3217](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3217) ![](https://img.shields.io/static/v1?label=Product&message=Chrome&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=114.0.5735.133%3C%20114.0.5735.133%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Use%20after%20free&color=brighgreen) ### Description Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) ### POC #### Reference - http://packetstormsecurity.com/files/173495/Chrome-device-OpenXrApiWrapper-InitSession-Heap-Use-After-Free.html #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/em1ga3l/cve-msrc-extractor