PT-2021-8116 · Google+1 · Google Chrome+1

Published

2021-03-17

·

Updated

2025-01-02

·

CVE-2023-7281

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 119.0.6045.105
Description The issue is related to an inappropriate implementation in Compositing, which can allow a remote attacker to perform UI spoofing via a crafted HTML page. This could be achieved by exploiting errors in the representation of information in the user interface.
Recommendations For versions prior to 119.0.6045.105, update to version 119.0.6045.105 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted HTML pages to minimize the risk of exploitation.

Exploit

Fix

UI Misrepresentation of Critical Information

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07569
CVE-2023-7281
DSA-5546-1

Affected Products

Astra Linux
Google Chrome