CVE-2023-2938: Inappropriate implementation in Picture In Picture
Chromium: CVE-2023-2938 Inappropriate implementation in Picture In Picture
Other sources
Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-2938?
CVE-2023-2938 has been classified with a medium severity rating due to the potential for inappropriate implementation issues in Chromium.
How do I fix CVE-2023-2938?
To fix CVE-2023-2938, update Microsoft Edge (Chromium-based) to version 114.0.1823.37 or later, or update Google Chrome to version 114.0.5735.90 or later.
Which versions of Chrome are affected by CVE-2023-2938?
Versions of Google Chrome prior to 114.0.5735.90 are affected by CVE-2023-2938.
Which versions of Edge are vulnerable to CVE-2023-2938?
CVE-2023-2938 affects Microsoft Edge versions up to 114.0.1823.37.
Does CVE-2023-2938 affect any other browsers?
CVE-2023-2938 specifically impacts Chromium-based browsers like Microsoft Edge and Google Chrome.