CVE-2023-4905: Inappropriate implementation in Prompts
Chromium: CVE-2023-4905 Inappropriate implementation in Prompts
Other sources
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-4905?
The severity of CVE-2023-4905 is Medium.
How can a remote attacker exploit CVE-2023-4905?
A remote attacker can exploit CVE-2023-4905 by spoofing security UI via a crafted HTML page.
Which browsers are affected by CVE-2023-4905?
Google Chrome versions prior to 117.0.5938.62 and Microsoft Edge (Chromium-based) versions up to 117.0.2045.31 are affected by CVE-2023-4905.
How can I check if my version of Google Chrome or Microsoft Edge (Chromium-based) is vulnerable?
You can check if your version of Google Chrome or Microsoft Edge (Chromium-based) is vulnerable by verifying the version number. If it is prior to 117.0.5938.62 for Google Chrome or 117.0.2045.31 for Microsoft Edge (Chromium-based), it is vulnerable.
What is the remedy for CVE-2023-4905?
Update Google Chrome to version 117.0.5938.62 or later, and Microsoft Edge (Chromium-based) to version 117.0.2045.31 or later to mitigate CVE-2023-4905.