CVE-2023-7012Improper Input Validation in Google Chrome

Severity
9.6CRITICALNVD
EPSS
0.1%
top 82.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateJul 17

Description

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0

Affected Packages5 packages

CVEListV5google/chrome117.0.5938.62117.0.5938.62
NVDgoogle/chrome< 117.0.5938.62
debiandebian/chromium< chromium 117.0.5938.62-1~deb12u1 (bookworm)
Debianchromium/chromium< 117.0.5938.62-1~deb11u1+3

🔴Vulnerability Details

2
GHSA
GHSA-c369-vvw4-mwwv: Insufficient data validation in Permission Prompts in Google Chrome prior to 1172024-07-17
OSV
CVE-2023-7012: Insufficient data validation in Permission Prompts in Google Chrome prior to 1172024-07-16

📋Vendor Advisories

2
Chrome
Stable Channel Update for Desktop: CVE-2023-70122023-09-12
Debian
CVE-2023-7012: chromium - Insufficient data validation in Permission Prompts in Google Chrome prior to 117...2023

💬Community

1
Bugzilla
Locally installed application can register “news” and “snews” protocols and get opened by default2024-07-17
CVE-2023-7012 — Improper Input Validation in Google | cvebase