XXE flaw in Chromium exposes local files (CVE-2023-4357)

XXE vulnerability in Chromium CVE-2023-4357 allows local file reading via XSLT; affects Chrome, Edge, Opera, and Brave. Recommended patch: update to 116.0.5845.96 or higher.

sábado, 16 de agosto de 2025 • 3 min read • Q2BSTUDIO Team

Artificial-Intelligence-

Author Hi, I'm Sharon, product manager at Chaitin Tech. We build SafeLine, an open source web application firewall designed against real threats. Additionally, our incident response center monitors and responds to RCE and authentication vulnerabilities across the stack to help developers stay safe.

Summary An XXE vulnerability was discovered in Chromium identified as CVE-2023-4357 that allows an attacker to read local files by bypassing Chromium's security sandbox, representing a serious privacy breach.

What caused the vulnerability The origin of the flaw lies in the integration of the libxslt library for XSLT processing. libxslt allows the use of the document function in XSL stylesheets; that function supports the inclusion of external entities and Chromium did not completely block that behavior within its sandbox. As a result, an attacker can create a malicious stylesheet that accesses file:// URLs via http(s):// requests. When Chromium runs with the --no-sandbox option, the attacker can access any file on the system without restrictions.

How it is exploited The attack is simple and silent. A malicious website includes a specially crafted SVG and a malicious XSL stylesheet. When visiting the page, Chromium loads the SVG and triggers the document function of libxslt, accessing local files in the background without notifications or obvious traces.

Impact It affects Chromium-based browsers such as Chrome, Edge, Opera, and Brave. Main risk: unauthorized access to local files. Elevated risk in headless applications and Electron applications that run Chromium with --no-sandbox. Possible consequences: leakage of sensitive data, privacy violations, and local reconnaissance for more advanced attacks.

Affected versions Chromium browsers with versions prior to 116.0.5845.96 and all applications using those affected versions.

Temporary mitigation Do not open suspicious or unknown links. Be cautious with sites that use SVG or XSLT. Avoid running embedded browsers with the --no-sandbox option unless absolutely necessary.

Permanent fix Google published a patch on August 31, 2023. Update your browser to version 116.0.5845.96 or higher. To update manually, open Chrome and go to chrome://settings/help and verify that the version is up to date. More information at https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop_15.html

Reproduction status The vulnerability was reproduced by Chaitin's emergency response lab on November 17, 2023. Public disclosure was made on October 25, 2023.

Timeline June 29, 2023 initial report by Igor Sak-Sakovskii. August 31, 2023 Chromium patch. October 25, 2023 public disclosure. November 17, 2023 reproduction and advisory by Chaitin Security.

References Chrome release updates report https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop_15.html and tracking in the Chromium bug tracker https://bugs.chromium.org/p/chromium/issues/detail?id=1458911

About Q2BSTUDIO Q2BSTUDIO is a software development company specialized in custom applications and custom software, with experience in artificial intelligence, cybersecurity, and aws and azure cloud services. We offer business intelligence services, AI for enterprises, AI agents, and Power BI solutions to improve decision-making. If you need security audits, cloud migrations, custom application development, or AI agent integration, our team can help you reduce risks and accelerate your digital transformation.

Featured services Custom application development, custom software, artificial intelligence solutions for enterprises, advanced cybersecurity, aws and azure cloud services, business intelligence services, AI agent implementation, and Power BI dashboards.

Final recommendation Keep your browsers and Chromium-based applications updated, avoid running components without a sandbox, and contact cybersecurity specialists if you suspect any compromise. For professional support and custom solutions in artificial intelligence and security, contact Q2BSTUDIO.

Contact For more information about our custom application services, custom software, artificial intelligence, cybersecurity, aws and azure cloud services, business intelligence services, AI for enterprises, AI agents, and Power BI, visit our website or request a consultation with our team.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.