First published: Fri Jan 20 2023(Updated: )
Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 111.0.5563.64 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Credit: chrome-cve-admin@google.com Roberto Ffrench-Davis @Lihaft
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <111.0.5563.64 | |
Apple iPhone OS | ||
Google Chrome | <111.0.5563.64 | 111.0.5563.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-1225 is a vulnerability in Google Chrome on iOS that allows a remote attacker to bypass the same origin policy through a crafted HTML page.
The severity of CVE-2023-1225 is medium.
A remote attacker can exploit CVE-2023-1225 by creating a specially crafted HTML page to bypass the same origin policy.
Versions of Google Chrome on iOS prior to 111.0.5563.64 are affected by CVE-2023-1225.
To fix CVE-2023-1225, update Google Chrome on iOS to version 111.0.5563.64 or later.