CVE-2023-2468: Inappropriate implementation in PictureInPicture
Chromium: CVE-2023-2468 Inappropriate implementation in PictureInPicture
Other sources
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-2468?
CVE-2023-2468 has been classified as a high severity vulnerability.
How do I fix CVE-2023-2468?
To fix CVE-2023-2468, update to the latest version of Chromium or Edge as recommended by their respective vendors.
Which versions of Chrome are affected by CVE-2023-2468?
CVE-2023-2468 affects Chrome versions up to 113.0.5672.63.
Is Microsoft Edge (Chromium-based) vulnerable to CVE-2023-2468?
Yes, Microsoft Edge (Chromium-based) is vulnerable to CVE-2023-2468 if it is running an affected version.
What should I do if I am using an affected version of Debian with CVE-2023-2468?
If using an affected version of Debian, upgrade the Chromium package to the latest stable version listed in your package manager.