CVE-2023-2311: Insufficient policy enforcement in File System API
Published Aug 19, 2022
·Updated
Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
Credit
Axel Chong
Affected Software
2 affected componentsFixes available
Google Chrome<112.0.5615.49
112.0.5615.49
Google Chrome<112.0.5615.49
Event History
Aug 19, 2022
CVE Published
12:00 AM
Jul 28, 2023
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-2311?
The severity of CVE-2023-2311 is classified as Medium by Chromium security.
2
How do I fix CVE-2023-2311?
To fix CVE-2023-2311, update Google Chrome to version 112.0.5615.49 or later.
3
What does CVE-2023-2311 exploit?
CVE-2023-2311 exploits insufficient policy enforcement in the File System API within Google Chrome.
4
Who is affected by CVE-2023-2311?
Users of Google Chrome versions prior to 112.0.5615.49 are affected by CVE-2023-2311.
5
Can CVE-2023-2311 be exploited remotely?
Yes, CVE-2023-2311 allows remote attackers to bypass filesystem restrictions via a crafted HTML page.