CVE-2023-4078 is a medium-severity vulnerability in Google Chrome versions prior to 115.0.5790.170. It stems from an inappropriate implementation in Extensions, allowing a malicious extension to inject scripts or HTML into privileged pages if a user is convinced to install it. The vulnerability carries a high CVSS score of 8.8, indicating high impact on confidentiality, integrity, and availability, with a network attack vector requiring user interaction. There is no evidence of active exploitation, and public exploit code is unavailable, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 115.0.5790.170, < 115.0.5790.170CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 115.0.5790.170CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.