Chromium: CVE-2023-3735 Inappropriate implementation in Web API Permission Prompts
An inappropriate implementation flaw was found in the Navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1248444
External References:
https://chromereleases.googleblog.com/2022/01/stable-channel-update-for-desktop.html
Chromium: CVE-2024-0805 Inappropriate implementation in Downloads
Chromium: CVE-2024-0811 Inappropriate implementation in Extensions API
Chromium: CVE-2023-5485 Inappropriate implementation in Autofill
Chromium: CVE-2023-5858 Inappropriate implementation in WebApp Provider
Chromium: CVE-2024-0333 Insufficient data validation in Extensions
Chromium: CVE-2024-0814 Incorrect security UI in Payments
Chromium: CVE-2023-6512 Inappropriate implementation in Web Browser UI
Chromium: CVE-2024-0810 Insufficient policy enforcement in DevTools
Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page.
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.
Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.
Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
Chromium: CVE-2024-0809 Inappropriate implementation in Autofill
Use after free in logging in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: Medium)
Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: Medium)
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)
Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2025-0448 Inappropriate implementation in Compositing
Chromium: CVE-2025-0441 Inappropriate implementation in Fenced Frames
Chromium: CVE-2025-0440 Inappropriate implementation in Fullscreen
Chromium: CVE-2025-0435 Inappropriate implementation in Navigation
Last updated 24 July 2024