CVE-2023-1816: Incorrect security UI in Picture In Picture
Chromium: CVE-2023-1816 Incorrect security UI in Picture In Picture
Other sources
Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-1816?
CVE-2023-1816 has been assigned a severity rating that indicates a significant security risk for vulnerable versions of Chromium-based browsers.
How do I fix CVE-2023-1816?
To fix CVE-2023-1816, update your Chromium-based browser to the latest version provided by your vendor.
Which software is affected by CVE-2023-1816?
CVE-2023-1816 affects Google Chrome and Microsoft Edge based on the Chromium engine, specifically versions prior to their remediation updates.
Is CVE-2023-1816 a remote code execution vulnerability?
Yes, CVE-2023-1816 is categorized as a vulnerability that could potentially allow remote code execution.
When was CVE-2023-1816 disclosed?
CVE-2023-1816 was disclosed as a significant vulnerability impacting various browsers using the Chromium framework.