
Reproduces CVE-2023-4357 in Google Chrome to demonstrate XML/XSLT-based file access bypass, with analysis and proof-of-concept for educational purposes.
This project is a final project for a Network Security course.
The project focuses on CVE-2023-4357, a vulnerability affecting Google Chrome versions prior to 116.0.5845.96. The vulnerability is related to the handling of XML/XSLT and can allow a malicious document to bypass intended file access restrictions.
I reproduced the vulnerability in a virtual machine using an older version of Google Chrome and analyzed how the XML document triggers the vulnerable behavior.
The provided XML/SVG file is used to reproduce the vulnerability and demonstrate unauthorized access to /etc/passwd.