CVE-2023-4357 is an insufficient input validation vulnerability in XML handling in Google Chrome affecting versions prior to 116.0.5845.96. Improper validation of untrusted XML input allows a remote attacker to use a crafted HTML page to bypass browser-enforced file access restrictions. The issue is classified by Chromium as medium severity and can undermine intended isolation and access control boundaries around local file access from web content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This is a minimal three-file proof-of-concept repository for CVE-2023-4357, not a framework module. The only exploit artifact is CVE-2023-4357.svg, an XML/SVG document containing an embedded XSLT stylesheet. Its DTD declares entities referencing file:///etc/passwd, and its XSLT template emits those entity values into XHTML elements, including a textarea intended to show the file contents. README.md identifies the issue as a Google Chrome XML/XSLT file-access restriction bypass affecting versions before 116.0.5845.96 and states that reproduction was performed using Chrome 114.0.5735.90 in a Linux VirtualBox VM. .gitattributes only configures Git text normalization. The repository contains no networking logic, callback infrastructure, persistence, command execution, or generalized payload customization; it is a local browser-rendering file-disclosure POC.
This repository is a proof-of-concept exploit for CVE-2023-4357, an XXE (XML External Entity) vulnerability in Google Chrome prior to version 116.0.5845.96 on Linux. The exploit consists of a crafted SVG file (src/d.svg) containing an XXE payload that attempts to read the contents of /etc/passwd from the victim's machine. The SVG also includes JavaScript to display the file path and contents in the browser, which could be further adapted to exfiltrate the data. The repository includes a simple Bash script (src/start_server.sh) to launch a Python HTTP server on port 8888, serving the malicious SVG file. The README provides step-by-step instructions for setting up the environment, running the server, and triggering the exploit by visiting http://127.0.0.1:8888/d.svg in a vulnerable Chrome browser. The exploit demonstrates the ability to bypass file access restrictions via a crafted HTML/SVG page, but does not include weaponized or automated exfiltration features.
This repository is a proof-of-concept exploit for Chrome CVE-2023-4357. It contains three files: a malicious SVG file (1.svg), a PHP script (exp.php), and a minimal README. The SVG file uses XSLT to load the PHP script, which outputs XML referencing sensitive files (/etc/passwd, /etc/hosts, /etc/group). Embedded JavaScript in the SVG exfiltrates the contents of these files to a remote HTTP endpoint (http://ip:port/). The exploit demonstrates how an attacker can leverage a browser vulnerability to read and exfiltrate sensitive files from a victim's system. The repository is structured as a simple POC, with the main logic split between the SVG (attack vector and exfiltration) and the PHP (file referencing and output).
This repository is a proof-of-concept (POC) exploit for CVE-2023-4357, a Google Chrome XXE (XML External Entity) vulnerability that allows arbitrary file read via SVG/XSLT processing. The repository contains four files: a README with usage instructions and a reference to a hosted malicious SVG, a Node.js server (server.js) that serves the malicious SVG (test.svg) and XSL (test.xsl) files, and the actual exploit payloads. The SVG file references the XSL file, which contains XXE payloads designed to read sensitive files from the victim's filesystem (such as /etc/passwd, /etc/hosts, and /etc/group). The exploit is triggered when a vulnerable Chrome browser opens the malicious SVG, either from the local server or the provided remote URL. The structure is typical for a POC: a simple web server, crafted payloads, and clear instructions for reproduction. No detection scripts or fake elements are present; the code is focused on demonstrating the vulnerability.
This repository provides a proof-of-concept exploit for CVE-2023-4357, a high-severity XXE vulnerability in Chromium-based browsers and related products. The exploit consists of two main files: d.svg (a self-contained malicious SVG file) and xss.html (an HTML payload embedding a base64-encoded SVG). The exploit leverages a flaw in libxslt's handling of XSLT and external entity references, allowing attackers to bypass cross-origin checks and read arbitrary local files from the victim's machine. The README.md provides detailed instructions for reproducing the exploit on Linux, Windows, and MacOS (WeChat Mac), including how to set up a local web server and access the payload. The exploit targets files such as /etc/passwd and c:/windows/system.ini, demonstrating the ability to exfiltrate sensitive local data. The attack vector is browser-based, requiring the victim to visit a malicious page or open a crafted SVG file. The repository is structured for ease of use, with each payload being self-contained and not requiring external dependencies.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.