CVE-2023-2726: Inappropriate implementation in WebApp Installs
Chromium: CVE-2023-2726 Inappropriate implementation in WebApp Installs
Other sources
Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-2726?
CVE-2023-2726 is a vulnerability related to inappropriate implementation in WebApp Installs in Google Chrome and Microsoft Edge (Chromium-based) versions prior to 113.0.5672.126.
What is the severity of CVE-2023-2726?
The severity of CVE-2023-2726 is Medium (Chromium security severity: Medium).
How can an attacker exploit CVE-2023-2726?
An attacker can exploit CVE-2023-2726 by convincing a user to install a malicious web app and bypassing the install dialog using a crafted HTML page.
Which software versions are affected by CVE-2023-2726?
Google Chrome versions prior to 113.0.5672.126, Microsoft Edge (Chromium-based) versions prior to 113.0.5672.126, and Microsoft Edge versions up to 113.0.1774.50 are affected by CVE-2023-2726.
How can I fix CVE-2023-2726?
To fix CVE-2023-2726, update Google Chrome to version 113.0.5672.126 or later, and update Microsoft Edge (Chromium-based) to version 113.0.5672.126 or later.