CVE-2023-3742

Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a local attacker to bypass device policy restrictions via physical access to the device. (Chromium security severity: High)
References
Link Resource
https://bugs.chromium.org/p/chromium/issues/detail?id=1443292 Exploit Mailing List
https://crbug.com/1443292 Exploit Mailing List
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*

History

04 Jan 2024, 14:30

Type Values Removed Values Added
References () https://bugs.chromium.org/p/chromium/issues/detail?id=1443292 - () https://bugs.chromium.org/p/chromium/issues/detail?id=1443292 - Exploit, Mailing List
References () https://crbug.com/1443292 - () https://crbug.com/1443292 - Exploit, Mailing List
First Time Google
Google chrome
Google chrome Os
CPE cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
Summary
  • (es) La aplicación insuficiente de políticas en ADB en Google Chrome en ChromeOS anterior a 114.0.5735.90 permitió a un atacante local omitir las restricciones de políticas del dispositivo mediante acceso físico al dispositivo. (Severidad de seguridad de Chrome: alta)
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8

20 Dec 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-20 16:15

Updated : 2024-01-04 14:30


NVD link : CVE-2023-3742

Mitre link : CVE-2023-3742

CVE.ORG link : CVE-2023-3742


JSON object : View

Products Affected

google

  • chrome
  • chrome_os