CVE-2023-3739: Insufficient validation of untrusted input in ChromeOS
Published Jul 20, 2023
·Updated
Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)
Credit
Rory McNamara.
Affected Software
2 affected components
Google Chrome<115.0.5790.131
Google Chrome OS
Event History
Jul 20, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeakness
Aug 1, 2023
CVE Published
via MITRE·10:39 PM
Data Sourced
via MITRE·10:39 PM
DescriptionWeakness
Data Sourced
11:15 PM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3739.
2
What is the severity of CVE-2023-3739?
The severity of CVE-2023-3739 is medium with a severity value of 6.3.
3
What is the affected software?
The affected software is Google Chrome on ChromeOS prior to version 115.0.5790.131.
4
How does the vulnerability in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 occur?
The vulnerability occurs due to insufficient validation of untrusted input in Chromad, allowing a remote attacker to execute arbitrary code via a crafted shell script.
5
How can I fix the vulnerability in CVE-2023-3739?
To fix the vulnerability, update Google Chrome on ChromeOS to version 115.0.5790.131 or later.