CVE-2023-6512 is a low-severity vulnerability in Google Chrome versions prior to 120.0.6099.62, affecting various distributions including Debian and Fedora. It stems from an inappropriate implementation in the Web Browser UI, allowing a remote attacker to potentially spoof iframe dialog context menu contents through a crafted HTML page. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack requiring user interaction, with a high impact on integrity but no impact on confidentiality or availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, with only one article mentioning it in the context of Microsoft's December 2023 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 120.0.6099.62, < 120.0.6099.62CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.