CVE-2023-2314: Insufficient data validation in DevTools
Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-1213
- CVE-2023-1214
- CVE-2023-1215
- CVE-2023-1216
- CVE-2023-1217
- CVE-2023-1218
- CVE-2023-1219
- CVE-2023-1220
- CVE-2023-1221
- CVE-2023-1222
- CVE-2023-1223
- CVE-2023-1224
- CVE-2023-1225
- CVE-2023-1226
- CVE-2023-1227
- CVE-2023-1228
- CVE-2023-1229
- CVE-2023-1230
- CVE-2023-1231
- CVE-2023-1232
- CVE-2023-1233
- CVE-2023-1234
- CVE-2023-1235
- CVE-2023-1236
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-2314.
What is the severity of CVE-2023-2314?
The severity of CVE-2023-2314 is medium.
What is the affected software?
The affected software is Google Chrome prior to version 111.0.5563.64.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by bypassing navigation restrictions via a crafted HTML page in DevTools in Google Chrome prior to version 111.0.5563.64.
Are there any references for this vulnerability?
Yes, there are references available. You can find them at the following links: [Link 1](https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.html), [Link 2](https://crbug.com/813542), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2LE64KGGOISKPKMYROSDT4K6QFVDIRF6/).