CVE-2023-0697 describes an inappropriate implementation vulnerability in Google Chrome on Android, specifically versions prior to 110.0.5481.77. This flaw allows a remote attacker, through a crafted HTML page, to spoof the security UI within Chrome's full-screen mode. Rated with a CVSS score of 6.5 (Medium), the vulnerability requires user interaction (UI:R) and could lead to high integrity impacts (I:H) by deceiving users about the authenticity of displayed content. Currently, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and limited community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 110.0.5481.77CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.