CVE-2023-7011 — User Interface (UI) Misrepresentation of Critical Information in Google Chrome
Severity
6.5MEDIUMNVD
EPSS
0.2%
top 56.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 16
Latest updateOct 16
Description
Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages5 packages
🔴Vulnerability Details
2🔍Detection Rules
1Suricata▶
ET WEB_SPECIFIC_APPS ByteValue webRead/open path Parameter Command Injection Attempt (CVE-2023-7011)↗2025-10-16