Fix for the CVE-2023-4357 vulnerability in the Chromium kernel

Updated at:

Background

The Chromium kernel vulnerability CVE-2023-4357 allows arbitrary file reading when the sandbox is disabled. The affected components include the UC kernel and Mini Programs. If you use these components, upgrade them as soon as possible by following this guide.

Upgrade details

  • If your client uses the 10.2.3 baseline, upgrade to version 10.2.3.39 or later. If you use a different custom baseline or have a separate dependency on 'com.alipay.android.phone.wallet:nebulaucsdk-build', contact the mPaaS helpdesk for assistance.

  • Upgrading the UC kernel may change some browser features. Perform regression testing on all services that use the UC browser, such as H5 containers and Mini Programs.

Important
  • This issue affects the H5 container and Mini Program components.

  • Perform thorough regression testing during the upgrade to ensure that your app's functionality, compatibility, and stability are not affected.

  • If you have customizations, such as a dependency on a different standalone UC kernel version, contact support to obtain an updated solution.