CVE-2023-5477: Inappropriate implementation in Installer
Chromium: CVE-2023-5477 Inappropriate implementation in Installer
Other sources
Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this Google Chrome issue?
The vulnerability ID of this issue is CVE-2023-5477.
What is the severity rating for vulnerability CVE-2023-5477?
The severity rating for vulnerability CVE-2023-5477 is medium (4.3).
What is the affected software for vulnerability CVE-2023-5477?
The affected software for vulnerability CVE-2023-5477 is Google Chrome version up to and excluding 118.0.5993.70.
How can a local attacker exploit vulnerability CVE-2023-5477?
A local attacker can exploit vulnerability CVE-2023-5477 by bypassing discretionary access control via a crafted command.
Where can I find more information about vulnerability CVE-2023-5477?
You can find more information about vulnerability CVE-2023-5477 in the following references: [link1](https://chromereleases.googleblog.com/2023/10/stable-channel-update-for-desktop_10.html) and [link2](https://crbug.com/1472558).