Vulnerability CVE-2023-1236: Information

Description

Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Published: March 8, 2023
Modified: March 10, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
chromiumsisyphus111.0.5563.64-alt1124.0.6367.78-alt1ALT-PU-2023-1403-1316434Fixed
chromiump10114.0.5735.90-alt0.p10.1119.0.6045.159-alt0.p10.1ALT-PU-2023-4119-2316826Fixed
chromium-gostsisyphus111.0.5563.64-alt1121.0.6167.160-alt1ALT-PU-2023-1450-1316788Fixed
yandex-browser-stablesisyphus23.5.1.659-alt124.1.3.845-alt1ALT-PU-2023-1928-1322308Fixed
yandex-browser-stablep1023.5.1.753-alt124.1.3.845-alt1ALT-PU-2023-2011-1322653Fixed
yandex-browser-stablec10f123.5.1.753-alt124.1.3.845-alt1ALT-PU-2023-2021-1322584Fixed
yandex-browser-stablec9f223.5.1.753-alt124.1.3.845-alt1ALT-PU-2023-1998-1322583Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End excliding
      111.0.5563.64