Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2023-0130
HistoryJan 10, 2023 - 8:15 p.m.

CVE-2023-0130

2023-01-1020:15:10
Debian Security Bug Tracker
security-tracker.debian.org
18
inappropriate implementation
fullscreen api
google chrome
android
omnibox
url bar
crafted html page
chromium security
medium severity
remote attacker

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.002 Low

EPSS

Percentile

53.2%

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.002 Low

EPSS

Percentile

53.2%