CVE-2023-4909: Inappropriate implementation in Interstitials
Chromium: CVE-2023-4909 Inappropriate implementation in Interstitials
Other sources
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-4909.
What is the severity level of CVE-2023-4909?
The severity level of CVE-2023-4909 is medium.
Which software products are affected by CVE-2023-4909?
The software products affected by CVE-2023-4909 are Google Chrome (up to version 117.0.5938.62), Microsoft Edge (Chromium-based) (up to version 117.0.2045.31).
How can a remote attacker exploit CVE-2023-4909?
A remote attacker can exploit CVE-2023-4909 by obfuscating security UI via a crafted HTML page.
Where can I find more information about CVE-2023-4909?
You can find more information about CVE-2023-4909 at the following references: [MSRC](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4909), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2023-4909), [Chrome Releases](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html).