CVE-2023-1234 describes a domain spoofing vulnerability in Google Chrome on Android, affecting versions prior to 111.0.5563.64. This low-severity flaw, with a CVSS score of 4.3 (Medium), could be triggered remotely by an unauthenticated attacker via a crafted HTML page, requiring user interaction but resulting in no confidentiality, integrity, or availability impact beyond the spoofing itself. There is no evidence of active exploitation, nor are public exploit modules available, and community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 111.0.5563.64CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 111.0.5563.64, < 111.0.5563.64CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.