CVE-2023-1823: Inappropriate implementation in FedCM
Chromium: CVE-2023-1823 Inappropriate implementation in FedCM
Other sources
Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-1823?
CVE-2023-1823 has been classified as a high severity vulnerability.
How do I fix CVE-2023-1823?
To fix CVE-2023-1823, you should update your Chromium-based browser to the latest version.
Which software is affected by CVE-2023-1823?
CVE-2023-1823 affects multiple versions of Google Chrome and Microsoft Edge based on Chromium.
What type of vulnerability is CVE-2023-1823?
CVE-2023-1823 is categorized as an inappropriate implementation vulnerability.
Is my version of Chromium vulnerable to CVE-2023-1823?
Versions of Chromium before 112.0.5615.49 are vulnerable to CVE-2023-1823 and should be updated.