CVE-2023-2937: Inappropriate implementation in Picture In Picture
Chromium: CVE-2023-2937 Inappropriate implementation in Picture In Picture
Other sources
Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-2937?
CVE-2023-2937 has been classified as a high severity vulnerability affecting Chromium and its derivatives.
How do I fix CVE-2023-2937?
To fix CVE-2023-2937, update affected software like Google Chrome or Chromium to the latest version that addresses this vulnerability.
Which software is affected by CVE-2023-2937?
CVE-2023-2937 affects versions of Google Chrome prior to 115.0.5790.102 and specific versions of Microsoft Edge built on Chromium.
When was CVE-2023-2937 disclosed?
CVE-2023-2937 was disclosed in May 2023 as part of a Chrome security update.
Is there a workaround for CVE-2023-2937?
There is no known workaround for CVE-2023-2937; updating to the latest software version is recommended.