Input validation error in Google Chromium - CVE-2023-4357

 

Input validation error in Google Chromium - CVE-2023-4357

Published: August 15, 2023 / Updated: April 19, 2024


Vulnerability identifier: #VU79545
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4357
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied input in XML in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


Affected software

Google Chromium
Microsoft Edge
Google Chrome
Gentoo Linux
Debian Linux
Fedora
Chrome OS
chromium
chromium (Debian package)
www-client/microsoft-edge
www-client/chromium
www-client/google-chrome

How to mitigate CVE-2023-4357

Update to version 116.0.5845.96.

Google Chromium - update to 116.0.5845.96
Microsoft Edge - update to 116.0.1938.54
Google Chrome - update to 116.0.5845.96
Chrome OS - addressed in versions 108.0.5359.242, 114.0.5735.332, 116.0.5845.120
chromium - addressed in versions 116.0.5845.96-1.el7, 116.0.5845.96-1.el8, 116.0.5845.96-1.el9, 116.0.5845.96-1.fc37, 116.0.5845.96-1.fc38
chromium (Debian package) - addressed in versions 116.0.5845.96-1~deb11u1, 116.0.5845.96-1~deb12u1
www-client/microsoft-edge - update to 120.0.2210.133
www-client/chromium - update to 120.0.6099.109
www-client/google-chrome - update to 120.0.6099.109

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins