CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-7012

CVSS 9.6v3.1pub. 2024-07-16upd. 2024-12-26

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)

🤖 AI Analysis
How it works

Insufficient data validation in the permission request display mechanism (Permission Prompts) allows an attacker to deliver a specially crafted file through a malicious application. Improper input data processing (CWE-20, CWE-138) leads to circumvention of the browser process isolation mechanism (sandbox). The attack requires user interaction — installation of a malicious application.

Impact

A successful attack could allow an attacker to escape the browser sandbox, potentially enabling access to the operating system outside the isolated Chrome environment, compromising the confidentiality, integrity, and availability of the system.

Mitigation & patch

Google Chrome should be updated to version 117.0.5938.62 or later. The update is available through the browser's automatic update mechanism and through the official Chrome Stable Channel.

Who is affected

Google Chrome in versions earlier than 117.0.5938.62

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Google Chrome

    APP
    Google
    < 117.0.5938.62
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2024-7971CRITICAL9.6⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption

CVE-2024-5274CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML

CVE-2024-4947CRITICAL9.6⚠ KEVPL ✓same product

Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)

CVE-2024-4671CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox