CVE-2023-1817: Insufficient policy enforcement in Intents
Chromium: CVE-2023-1817 Insufficient policy enforcement in Intents
Other sources
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-1817?
CVE-2023-1817 is a vulnerability in Google Chrome on Android that allows a remote attacker to bypass navigation restrictions via a crafted HTML page.
What is the severity of CVE-2023-1817?
The severity of CVE-2023-1817 is Medium (6.5).
Which software versions are affected by CVE-2023-1817?
Microsoft Edge (version up to-exclusive 112.0.1722.34), Microsoft Edge (Chromium-based), Google Chrome (version up to-exclusive 112.0.5615.49), and Fedora 37 are affected by CVE-2023-1817.
How can I fix CVE-2023-1817 in Microsoft Edge?
To fix CVE-2023-1817 in Microsoft Edge, update to the latest version from the official Microsoft Edge website or use the automatic update feature.
How can I fix CVE-2023-1817 in Google Chrome?
To fix CVE-2023-1817 in Google Chrome, update to version 112.0.5615.49 or later.
How can I fix CVE-2023-1817 in Fedora?
To fix CVE-2023-1817 in Fedora, update to a version higher than 37, if available.
Where can I find more information about CVE-2023-1817?
You can find more information about CVE-2023-1817 at the official Microsoft Security Response Center (MSRC) website, Debian Security Tracker, and the Google Chrome Releases Blog.