CVE-2023-4902: Inappropriate implementation in Input
Chromium: CVE-2023-4902 Inappropriate implementation in Input
Other sources
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-4902.
What is the severity of CVE-2023-4902?
The severity of CVE-2023-4902 is Medium (4.3).
Which software versions are affected by CVE-2023-4902?
Google Chrome versions up to 117.0.5938.62 and Microsoft Edge versions up to 117.0.2045.31 are affected by CVE-2023-4902.
How can a remote attacker exploit CVE-2023-4902?
A remote attacker can exploit CVE-2023-4902 by spoofing security UI via a crafted HTML page.
How can I fix CVE-2023-4902?
To fix CVE-2023-4902, update Google Chrome to version 117.0.5938.62 or later and Microsoft Edge to version 117.0.2045.31 or later.