CVE-2023-5477 is a low-severity vulnerability in the Google Chrome installer, affecting versions prior to 118.0.5993.70, as well as Debian-based Chrome installations. It allows a local attacker to bypass discretionary access control through a crafted command due to an inappropriate implementation. The CVSS score is 4.3 (Medium), indicating a low impact on integrity and no impact on confidentiality or availability, requiring user interaction for exploitation. There is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 118.0.5993.70, < 118.0.5993.70CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 118.0.5993.70CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.