CVE-2023-4357
HIGH 8.8EPSS 47.1%
Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS
- 47.12% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2023-08-15
- Updated
- 2025-02-13
Proof-of-concept exploits (6)
- CamillaFranceschini/CVE-2023-43570★ · 2024-06-20
- WinnieZy/CVE-2023-43570★ · 2024-01-09
- lon5948/CVE-2023-4357-Exploitation4★ · 2024-04-13
- passwa11/CVE-2023-4357-APT-Style-exploitation0★ · 2023-11-21
- sunu11/chrome-CVE-2023-43574★ · 2023-11-29
- xcanwin/CVE-2023-4357-Chrome-XXE230★ · 2025-04-04