Security Research

CVE-2023-4357 Chrome XEE on WebBrowsers: from XML external entity to arbitrary file read

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of Chrome XML parser and file read

The Chrome browser’s XML parser does not disable external entity loading when processing user-controlled XML. An attacker crafts malicious XML to read local files.

Unlock to view this content.