CVE-2023-4903: Inappropriate implementation in Custom Mobile Tabs
Chromium: CVE-2023-4903 Inappropriate implementation in Custom Mobile Tabs
Other sources
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4903?
CVE-2023-4903 is a vulnerability that involves inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android, allowing a remote attacker to spoof security UI via a crafted HTML page.
What is the severity of CVE-2023-4903?
CVE-2023-4903 has a severity level of Medium.
Which software is affected by CVE-2023-4903?
CVE-2023-4903 affects Google Chrome on Android prior to version 117.0.5938.62 and Microsoft Edge (Chromium-based) prior to version 117.0.2045.31.
How can a remote attacker exploit CVE-2023-4903?
A remote attacker can exploit CVE-2023-4903 by creating a crafted HTML page to spoof security UI.
What is the recommended remedy for CVE-2023-4903?
The recommended remedy for CVE-2023-4903 is to update Google Chrome on Android to version 117.0.5938.62 or later, and Microsoft Edge (Chromium-based) to version 117.0.2045.31 or later.