CVE-2023-5859: Incorrect security UI in Picture In Picture
Chromium: CVE-2023-5859 Incorrect security UI in Picture In Picture
Other sources
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-5859?
The severity of CVE-2023-5859 is Low.
How does CVE-2023-5859 affect Chromium-based Microsoft Edge?
CVE-2023-5859 affects Chromium-based Microsoft Edge versions prior to 119.0.6045.105, allowing a remote attacker to perform domain spoofing via a crafted local HTML page.
How can I fix CVE-2023-5859 in Chromium-based Microsoft Edge?
To fix CVE-2023-5859 in Chromium-based Microsoft Edge, update to version 119.0.6045.105 or later.
How does CVE-2023-5859 affect Microsoft Edge?
CVE-2023-5859 affects Microsoft Edge versions up to 119.0.2151.44, allowing a remote attacker to perform domain spoofing via a crafted local HTML page.
How can I fix CVE-2023-5859 in Microsoft Edge?
To fix CVE-2023-5859 in Microsoft Edge, update to version 119.0.2151.44 or later.