CVE-2023-4907: Inappropriate implementation in Intents
Chromium: CVE-2023-4907 Inappropriate implementation in Intents
Other sources
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-4907.
What is the severity of CVE-2023-4907?
The severity of CVE-2023-4907 is medium.
What is the affected software?
The affected software includes Google Chrome on Android prior to version 117.0.5938.62, Microsoft Edge (Chromium-based) prior to version 117.0.2045.31, and Chromium packages prior to version 117.0.5938.62 on Debian.
How can the vulnerability be exploited?
The vulnerability can be exploited by a remote attacker to obfuscate security UI via a crafted HTML page.
What is the remediation for CVE-2023-4907?
The remediation for CVE-2023-4907 is to update to the specified patched versions of Google Chrome, Microsoft Edge (Chromium-based), or Chromium packages.