CVE-2023-0131: Inappropriate implementation in iframe Sandbox
Published Aug 28, 2022
·Updated
Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a crafted HTML page. (Chromium security severity: Medium)
Credit
NDevTK
Affected Software
2 affected componentsFixes available
Google Chrome<109.0.5414.74
109.0.5414.74
Google Chrome<109.0.5414.74
Event History
Aug 28, 2022
CVE Published
12:00 AM
Jan 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-0131?
CVE-2023-0131 has a medium severity rating as per Chromium's security assessment.
2
How do I fix CVE-2023-0131?
The issue can be resolved by updating Google Chrome to version 109.0.5414.74 or later.
3
What type of attack does CVE-2023-0131 enable?
CVE-2023-0131 enables remote attackers to bypass file download restrictions through a crafted HTML page.
4
Which versions of Google Chrome are affected by CVE-2023-0131?
Google Chrome versions prior to 109.0.5414.74 are affected by CVE-2023-0131.
5
Is there a workaround for CVE-2023-0131?
There is no known workaround for CVE-2023-0131, so updating to the latest version is necessary.