PT-2024-13257 · Google · Chromium
Andrea Palanca
·
Published
2024-03-05
·
Updated
2024-10-17
·
CVE-2023-45593
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AiLux imx6 bundle versions prior to imx6 1.0.7-2
Description
A vulnerability in the embedded Chromium browser, concerning the handling of alternative URLs other than "http://localhost", allows a physical attacker to read arbitrary files on the file system, alter the configuration of the embedded browser, and have other unspecified impacts to the confidentiality, integrity, and availability of the device.
Recommendations
For AiLux imx6 bundle versions prior to imx6 1.0.7-2, update to version imx6 1.0.7-2 or later to resolve the issue. As a temporary workaround, consider restricting access to the embedded Chromium browser until a patch is available. Avoid using alternative URLs other than "http://localhost" in the embedded browser until the issue is resolved.
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chromium