CVE-2023-4908: Inappropriate implementation in Picture in Picture
Chromium: CVE-2023-4908 Inappropriate implementation in Picture in Picture
Other sources
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-4908?
The severity of CVE-2023-4908 is medium.
What is the affected software for CVE-2023-4908?
The affected software for CVE-2023-4908 includes Google Chrome, Microsoft Edge, and Microsoft Edge (Chromium-based).
How can a remote attacker exploit CVE-2023-4908?
A remote attacker can exploit CVE-2023-4908 by spoofing security UI via a crafted HTML page.
How can I fix CVE-2023-4908 in Google Chrome?
To fix CVE-2023-4908 in Google Chrome, update to version 117.0.5938.62 or later.
How can I fix CVE-2023-4908 in Microsoft Edge (Chromium-based)?
To fix CVE-2023-4908 in Microsoft Edge (Chromium-based), update to the latest version.