CVE-2023-4901: Inappropriate implementation in Prompts
Chromium: CVE-2023-4901 Inappropriate implementation in Prompts
Other sources
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4901?
CVE-2023-4901 is a vulnerability in the Prompts implementation in Google Chrome which allows a remote attacker to potentially spoof security UI.
What is the severity of CVE-2023-4901?
The severity of CVE-2023-4901 is medium (4.3).
Which software is affected by CVE-2023-4901?
Microsoft Edge (Chromium-based) before version 117.0.2045.31, Google Chrome before version 117.0.5938.62, and Debian Chromium before version 90.0.4430.212-1~deb10u1, 112.0.5615.138-1~deb11u1, 114.0.5735.198-1~deb12u1, and 116.0.5845.140-1 are affected by CVE-2023-4901.
How can a remote attacker exploit CVE-2023-4901?
A remote attacker can exploit CVE-2023-4901 by creating a crafted HTML page that can potentially spoof security UI.
Where can I find more information about CVE-2023-4901?
You can find more information about CVE-2023-4901 on the Microsoft Security Response Center (MSRC) website, the Debian security tracker, and the Google Chrome Releases blog.