PT-2023-2136 · Google+3 · Google Chrome+3

강우진

·

Publicado

2023-04-04

·

Atualizado

2024-11-29

·

CVE-2023-1822

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 112.0.5615.49
Description The issue is related to incorrect security UI in Navigation, allowing a remote attacker to perform domain spoofing via a crafted HTML page. This is due to insufficient validation of user-input data. The exploitation of this issue may enable a remote attacker to conduct a spoofing attack using a specially crafted web page.
Recommendations For versions prior to 112.0.5615.49, update to version 112.0.5615.49 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable Navigation features until the update is applied.

Exploit

Correção

UI Misrepresentation of Critical Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-1659
ALT-PU-2023-1928
ALT-PU-2023-1998
ALT-PU-2023-2011
ALT-PU-2023-2021
ALT-PU-2023-4119
ALT-PU-2023-5790
ALT-PU-2024-14286
ALT-PU-2024-14830
BDU:2023-01874
CVE-2023-1822
DSA-5386-1
OPENSUSE-SU-2023:0092-1
OPENSUSE-SU-2024:12844-1
OPENSUSE-SU-2024:12948-1
USN-6021-1

Produtos afetados

Alt Linux
Astra Linux
Google Chrome
Ubuntu