First published: Sun Dec 25 2022(Updated: )
Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Credit: chrome-cve-admin@google.com Thomas Orlita
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <111.0.5563.64 | |
Google Chrome | <111.0.5563.64 | 111.0.5563.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-1224 is classified as a Medium severity vulnerability.
CVE-2023-1224 allows remote attackers to bypass navigation restrictions in the Web Payments API.
CVE-2023-1224 affects Google Chrome versions prior to 111.0.5563.64.
To fix CVE-2023-1224, users should update Google Chrome to version 111.0.5563.64 or later.
CVE-2023-1224 can be exploited via a crafted HTML page by remote attackers.