CVE-2023-4357: Insufficient validation of untrusted input in XML
Chromium: CVE-2023-4357 Insufficient validation of untrusted input in XML
Other sources
Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-4369
- CVE-2023-20593
- CVE-2023-4211
- CVE-2023-4128
- CVE-2023-4147
- CVE-2023-3390
- CVE-2023-32804
- CVE-2022-40982
- CVE-2023-2312
- CVE-2023-4349
- CVE-2023-4350
- CVE-2023-4351
- CVE-2023-4352
- CVE-2023-4353
- CVE-2023-4354
- CVE-2023-4355
- CVE-2023-4356
- CVE-2023-4358
- CVE-2023-4359
- CVE-2023-4360
- CVE-2023-4361
- CVE-2023-4362
- CVE-2023-4363
- CVE-2023-4364
- CVE-2023-4365
- CVE-2023-4366
- CVE-2023-4367
- CVE-2023-4368
- CVE-2023-21264
- CVE-2020-29374
Frequently Asked Questions
What is CVE-2023-4357?
CVE-2023-4357 is a vulnerability in Chromium that allows a remote attacker to bypass file access restrictions via a crafted HTML page.
What is the severity of CVE-2023-4357?
CVE-2023-4357 has a severity level of 8.8 (high).
Which software is affected by CVE-2023-4357?
The software affected by CVE-2023-4357 includes Microsoft Edge (Chromium-based), Google Chrome, Debian Debian Linux, and Fedoraproject Fedora.
How do I fix CVE-2023-4357 in Microsoft Edge?
To fix CVE-2023-4357 in Microsoft Edge, update to version 116.0.1938.54 or newer.
How do I fix CVE-2023-4357 in Google Chrome?
To fix CVE-2023-4357 in Google Chrome, update to version 116.0.5845.96 or newer.
How do I fix CVE-2023-4357 in Debian Debian Linux?
To fix CVE-2023-4357 in Debian Debian Linux, update to version 11.0 or 12.0, depending on your installed version.
How do I fix CVE-2023-4357 in Fedoraproject Fedora?
To fix CVE-2023-4357 in Fedoraproject Fedora, update to version 38 or newer.