CVE-2023-5479: Inappropriate implementation in Extensions API
Chromium: CVE-2023-5479 Inappropriate implementation in Extensions API
Other sources
Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-5479?
The severity of CVE-2023-5479 is Medium (6.5).
What software is affected by CVE-2023-5479?
Google Chrome versions up to 118.0.5993.70 are affected by CVE-2023-5479.
How can an attacker exploit CVE-2023-5479?
An attacker can exploit CVE-2023-5479 by convincing a user to install a malicious extension and bypassing an enterprise policy via a crafted HTML page.
How can I fix CVE-2023-5479?
To fix CVE-2023-5479, update Google Chrome to version 118.0.5993.70 or later.
Where can I find more information about CVE-2023-5479?
More information about CVE-2023-5479 can be found in the reference links: [1](https://chromereleases.googleblog.com/2023/10/stable-channel-update-for-desktop_10.html) and [2](https://crbug.com/1471253).