CVE-2023-2313: Inappropriate implementation in Sandbox
Published Jun 14, 2022
·Updated
Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)
Credit
Anonymous
Affected Software
3 affected componentsFixes available
Google Chrome<112.0.5615.49
112.0.5615.49
Google Chrome<112.0.5615.49
Microsoft Windows
Event History
Jun 14, 2022
CVE Published
12:00 AM
Jul 28, 2023
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
DescriptionWeakness
Jul 29, 2023
Data Sourced
12:15 AM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-2313?
The severity of CVE-2023-2313 is classified as High.
2
How do I fix CVE-2023-2313?
To fix CVE-2023-2313, update Google Chrome to version 112.0.5615.49 or later.
3
What does CVE-2023-2313 affect?
CVE-2023-2313 affects Google Chrome versions prior to 112.0.5615.49 on Windows.
4
What type of vulnerability is CVE-2023-2313?
CVE-2023-2313 is an inappropriate implementation in the Sandbox of Google Chrome.
5
Can CVE-2023-2313 allow an attack?
Yes, CVE-2023-2313 allows a remote attacker to perform arbitrary read/write operations if they compromised the renderer process.