CVE-2023-4764: Incorrect security UI in BFCache
Chromium: CVE-2023-4764 Incorrect security UI in BFCache
Other sources
Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4764?
CVE-2023-4764 is a vulnerability in Chromium that allows a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
What is the severity of CVE-2023-4764?
The severity of CVE-2023-4764 is classified as medium with a CVSS score of 6.5.
Which software products are affected by CVE-2023-4764?
Microsoft Edge (Chromium-based), Google Chrome, and Debian Linux are affected by CVE-2023-4764.
How can I fix CVE-2023-4764 in Microsoft Edge?
To fix CVE-2023-4764 in Microsoft Edge, update to version 116.0.1938.1 or later. Refer to the Microsoft Edge release notes for security updates.
How can I fix CVE-2023-4764 in Google Chrome?
To fix CVE-2023-4764 in Google Chrome, update to version 116.0.5845.179 or later.
How can I fix CVE-2023-4764 in Debian Linux?
To fix CVE-2023-4764 in Debian Linux, update the Chromium package to version 117.0.5938.62-1~deb10u1, 117.0.5938.62-1~deb11u1, 117.0.5938.62-1~deb12u1, or later.