CVE-2023-3740: Insufficient validation of untrusted input in Themes
Chromium: CVE-2023-3740 Insufficient validation of untrusted input in Themes
Other sources
Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-3740?
CVE-2023-3740 has been rated as a high severity vulnerability affecting Chromium-based browsers.
How do I fix CVE-2023-3740?
To fix CVE-2023-3740, update Microsoft Edge or Google Chrome to the latest version available beyond 115.0.1901.183 for Edge and 115.0.5790.98 for Chrome.
Which browsers are affected by CVE-2023-3740?
CVE-2023-3740 affects Microsoft Edge (Chromium-based) and Google Chrome prior to version 115.0.5790.98.
What type of vulnerability is CVE-2023-3740?
CVE-2023-3740 is categorized as an insufficient validation issue within Chromium.
Who assigned CVE-2023-3740?
CVE-2023-3740 was assigned by the Chrome security team.