CVE-2023-5487: Inappropriate implementation in Fullscreen
Chromium: CVE-2023-5487 Inappropriate implementation in Fullscreen
Other sources
Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this Google Chrome vulnerability?
The vulnerability ID for this Google Chrome vulnerability is CVE-2023-5487.
What is the severity level of CVE-2023-5487?
The severity level of CVE-2023-5487 is medium (6.5).
How can an attacker exploit CVE-2023-5487?
An attacker can exploit CVE-2023-5487 by convincing a user to install a malicious extension, allowing them to bypass navigation restrictions via a crafted Chrome Extension.
Which version of Google Chrome is affected by CVE-2023-5487?
Google Chrome versions prior to 118.0.5993.70 are affected by CVE-2023-5487.
How can I fix CVE-2023-5487?
To fix CVE-2023-5487, users should update their Google Chrome browser to version 118.0.5993.70 or later.