PT-2023-8236 · Google · Google Chrome

CVE-2023-3742

·

Publicado

2023-05-08

·

Atualizado

2024-01-04

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome on ChromeOS versions prior to 114.0.5735.90
Description The issue is related to insufficient policy enforcement in the Android Debug Bridge (ADB) component of Google Chrome on ChromeOS. This allows a local attacker with physical access to the device to bypass device policy restrictions. The severity of this issue is considered high.
Recommendations For Google Chrome on ChromeOS versions prior to 114.0.5735.90, update to version 114.0.5735.90 or later to resolve the issue. As a temporary workaround, consider restricting physical access to devices to minimize the risk of exploitation.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-00266
CVE-2023-3742

Produtos afetados

Google Chrome