CVE-2023-45592
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Mar 5, 2024
CWE ID 250
Summary
CVE-2023-45592 is a newly identified vulnerability that affects the AiLux imx6 bundle. The root cause is an "Execution with Unnecessary Privileges" issue (CWE-250) in the embedded Chromium browser, which is made worse by the binary being run with the "--no-sandbox" option and root privileges. Successful attacks against this browser can have more severe consequences due to this vulnerability. Specifically, the imx6 bundle below version imx6_1.0.7-2 is susceptible to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.