CVE-2023-3734: Inappropriate implementation in Picture In Picture
Chromium: CVE-2023-3734 Inappropriate implementation in Picture In Picture
Other sources
Inappropriate implementation in Picture In Picture in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-3734?
CVE-2023-3734 is classified as a medium severity vulnerability.
How do I fix CVE-2023-3734?
You can fix CVE-2023-3734 by updating Microsoft Edge to version 115.0.1901.183 or Google Chrome to version 115.0.5790.98.
What types of software are affected by CVE-2023-3734?
CVE-2023-3734 affects Microsoft Edge and Google Chrome versions below the specified thresholds.
Is there a workaround for CVE-2023-3734?
No specific workaround is provided for CVE-2023-3734; the recommended action is to update the affected browsers.
What can happen if I do not address CVE-2023-3734?
If CVE-2023-3734 is not addressed, it may lead to unexpected behavior or security issues in the affected browsers.