CVE-2023-4077 is a medium-severity vulnerability in Google Chrome, affecting versions prior to 115.0.5790.170. It stems from insufficient data validation in Extensions, allowing an attacker to inject scripts or HTML into privileged pages if a user installs a malicious extension. With a CVSS score of 8.8 (High), this vulnerability requires user interaction (installing a malicious extension) but can lead to high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 115.0.5790.170, < 115.0.5790.170CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 115.0.5790.170CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.