MEDIUM
Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension
Published Oct 11, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.60%
Description
Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
Affected products
-
Affected
- ≥ 118.0.5993.70, < 118.0.5993.70
Configuration 2
OR
- 37
- 38
Configuration 3
- 37
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (9)
- https://chromereleases.googleblog.com/2023/10/stable-channel-update-for-desktop_10.html Release NotesVendor Advisory
- https://crbug.com/1062251 Permissions Required
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57801 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F5QCMP6KKWPDZZLFU7YXSZDHEKOE7BXO/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4GHJ3FK5NPHDRUR4OJOI4UU6FKSOOGG/ Mailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202311-11 Third Party Advisory
- https://security.gentoo.org/glsa/202312-07 Third Party Advisory
- https://security.gentoo.org/glsa/202401-34
- https://www.debian.org/security/2023/dsa-5526 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://chromereleases.googleblog.com/2023/10/stable-channel-update-for-desktop_10.html | Release NotesVendor Advisory | |
| https://crbug.com/1062251 | Permissions Required | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57801 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F5QCMP6KKWPDZZLFU7YXSZDHEKOE7BXO/ | Mailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4GHJ3FK5NPHDRUR4OJOI4UU6FKSOOGG/ | Mailing ListThird Party Advisory | |
| https://security.gentoo.org/glsa/202311-11 | Third Party Advisory | |
| https://security.gentoo.org/glsa/202312-07 | Third Party Advisory | |
| https://security.gentoo.org/glsa/202401-34 | ||
| https://www.debian.org/security/2023/dsa-5526 | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Oct 11, 2023
Updated Feb 13, 2025
Reserved Oct 10, 2023
Link CVE-2023-5487
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data