
Cloud Vulnerability DB
A community-led vulnerabilities database
A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682. The vulnerability, identified as CVE-2023-26226, was discovered by researcher khangkito through the Yandex BugBounty program and was disclosed on May 30, 2025 (NVD, Yandex BugBounty).
The vulnerability is classified as a Use After Free (CWE-416) memory corruption issue. It received a CVSS v4.0 score of 7.4 (HIGH) with the vector string CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:H/SC:H/SI:H/SA:H (NVD, Wiz).
The vulnerability could potentially lead to memory corruption in Yandex Browser, which may result in program crashes or potential code execution. The CVSS scoring indicates high impacts on confidentiality, availability, and system/integrity components (Wiz).
Users should upgrade to Yandex Browser for Desktop version 24.4.0.682 or later to address this vulnerability (Yandex BugBounty).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."