PT-2022-1796 · Google+2 · Google Chrome+2
Alesandro Ortiz
·
Published
2022-01-04
·
Updated
2024-06-15
·
CVE-2022-0110
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 97.0.4692.71
Description
The issue is related to an incorrect implementation of the security interface in Autofill, allowing a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. This is due to insufficient input validation in the Autofill function. The exploitation of this issue may allow a remote attacker to impact the integrity of protected information.
Recommendations
For Google Chrome versions prior to 97.0.4692.71, update to version 97.0.4692.71 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Autofill feature until a patch is applied. Avoid using crafted HTML pages that may exploit this issue.
Exploit
Fix
Clickjacking
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Suse