CVE-2023-1230: Inappropriate implementation in WebApp Installs
Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious WebApp to spoof the contents of the PWA installer via a crafted HTML page. (Chromium security severity: Medium)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-1213
- CVE-2023-1214
- CVE-2023-1215
- CVE-2023-1216
- CVE-2023-1217
- CVE-2023-1218
- CVE-2023-1219
- CVE-2023-1220
- CVE-2023-1221
- CVE-2023-1222
- CVE-2023-1223
- CVE-2023-1224
- CVE-2023-1225
- CVE-2023-1226
- CVE-2023-1227
- CVE-2023-1228
- CVE-2023-1229
- CVE-2023-1231
- CVE-2023-2314
- CVE-2023-1232
- CVE-2023-1233
- CVE-2023-1234
- CVE-2023-1235
- CVE-2023-1236
Frequently Asked Questions
What is the severity of CVE-2023-1230?
The severity of CVE-2023-1230 is classified as Medium.
How do I fix CVE-2023-1230?
To fix CVE-2023-1230, update Google Chrome on Android to version 111.0.5563.64 or later.
What causes CVE-2023-1230?
CVE-2023-1230 is caused by an inappropriate implementation in WebApp Installs in Google Chrome on Android.
Which versions of Google Chrome are affected by CVE-2023-1230?
Google Chrome versions prior to 111.0.5563.64 on Android are affected by CVE-2023-1230.
Can CVE-2023-1230 allow an attacker to spoof content?
Yes, CVE-2023-1230 allows an attacker to spoof the contents of the PWA installer through a crafted HTML page.