CVE-2023-5485: Inappropriate implementation in Autofill
Chromium: CVE-2023-5485 Inappropriate implementation in Autofill
Other sources
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-5485.
What is the severity of CVE-2023-5485?
The severity of CVE-2023-5485 is medium.
What is the affected software for CVE-2023-5485?
The affected software for CVE-2023-5485 is Google Chrome prior to version 118.0.5993.70.
What is the security risk associated with CVE-2023-5485?
The security risk associated with CVE-2023-5485 is a remote attacker bypassing autofill restrictions via a crafted HTML page.
How can I fix CVE-2023-5485?
To fix CVE-2023-5485, update Google Chrome to version 118.0.5993.70 or later.