CVE-2023-4900: Inappropriate implementation in Custom Tabs
Chromium: CVE-2023-4900 Inappropriate implementation in Custom Tabs
Other sources
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4900?
CVE-2023-4900 is a vulnerability in Custom Tabs in Google Chrome on Android that allows a remote attacker to obfuscate a permission prompt via a crafted HTML page.
What is the severity of CVE-2023-4900?
The severity of CVE-2023-4900 is Medium.
How can I fix CVE-2023-4900?
To fix CVE-2023-4900, update your Google Chrome on Android to version 117.0.5938.62 or later.
Is Microsoft Edge affected by CVE-2023-4900?
Yes, the Chromium-based version of Microsoft Edge is affected by CVE-2023-4900. Update to the latest version to fix the vulnerability.
What is the reference for CVE-2023-4900?
You can find more information about CVE-2023-4900 at the following references: [1][2][3].