First published: Fri Aug 19 2022(Updated: )
Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
Credit: chrome-cve-admin@google.com Axel Chong
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <112.0.5615.49 | |
Google Chrome | <112.0.5615.49 | 112.0.5615.49 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2023-2311 is classified as Medium by Chromium security.
To fix CVE-2023-2311, update Google Chrome to version 112.0.5615.49 or later.
CVE-2023-2311 exploits insufficient policy enforcement in the File System API within Google Chrome.
Users of Google Chrome versions prior to 112.0.5615.49 are affected by CVE-2023-2311.
Yes, CVE-2023-2311 allows remote attackers to bypass filesystem restrictions via a crafted HTML page.