CVE-2023-4906: Insufficient policy enforcement in Autofill
Chromium: CVE-2023-4906 Insufficient policy enforcement in Autofill
Other sources
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-4906?
The severity of CVE-2023-4906 is medium, with a severity value of 4.3.
How does CVE-2023-4906 affect Microsoft Edge (Chromium-based)?
CVE-2023-4906 affects Microsoft Edge (Chromium-based) versions prior to 117.0.5938.62.
How does CVE-2023-4906 affect Microsoft Edge?
CVE-2023-4906 affects Microsoft Edge versions prior to 117.0.2045.31.
How does CVE-2023-4906 affect Google Chrome?
CVE-2023-4906 affects Google Chrome versions prior to 117.0.5938.62.
Are there any remedies available for CVE-2023-4906?
Remedies for CVE-2023-4906 are available from Microsoft, Debian, and Google Chrome.