First published: Mon Jul 03 2023(Updated: )
Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Credit: Axel Chong chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <119.0.6045.105 | 119.0.6045.105 |
Google Chrome (Trace Event) | <119.0.6045.105 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-7011 has a medium severity rating according to Chromium's security classification.
To mitigate CVE-2023-7011, update Google Chrome to version 119.0.6045.105 or later.
CVE-2023-7011 involves a remote attacker being able to spoof the contents of the Omnibox via a crafted HTML page.
CVE-2023-7011 affects all versions of Google Chrome prior to 119.0.6045.105.
Yes, the impacted product is Google Chrome, specifically versions earlier than 119.0.6045.105.