CVE-2023-2464: Inappropriate implementation in PictureInPicture
Chromium: CVE-2023-2464 Inappropriate implementation in PictureInPicture
Other sources
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-2464?
CVE-2023-2464 has been classified with medium severity as it involves inappropriate implementation in Chromium.
How do I fix CVE-2023-2464?
To fix CVE-2023-2464, update Chromium or your Chromium-based browser to the latest version available.
Which browsers are affected by CVE-2023-2464?
CVE-2023-2464 affects Chromium-based browsers including Google Chrome and Microsoft Edge.
Are there any workarounds for CVE-2023-2464?
No specific workarounds for CVE-2023-2464 are recommended; users should update to the latest versions.
What versions are vulnerable to CVE-2023-2464?
Versions of Chromium prior to the updates released after May 2023 are vulnerable to CVE-2023-2464.