PT-2023-8236 · Google · Google Chrome

Published

2023-05-08

·

Updated

2024-01-04

·

CVE-2023-3742

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome on ChromeOS versions prior to 114.0.5735.90
Description The issue is related to insufficient policy enforcement in the Android Debug Bridge (ADB) component of Google Chrome on ChromeOS. This allows a local attacker with physical access to the device to bypass device policy restrictions. The severity of this issue is considered high.
Recommendations For Google Chrome on ChromeOS versions prior to 114.0.5735.90, update to version 114.0.5735.90 or later to resolve the issue. As a temporary workaround, consider restricting physical access to devices to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-00266
CVE-2023-3742

Affected Products

Google Chrome