PT-2022-2091 · Google+2 · Google Chrome+2

Andr.Ess

·

Published

2022-01-18

·

Updated

2024-06-15

·

CVE-2022-1132

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 100.0.4896.60
Description The issue is related to an inappropriate implementation in the Virtual Keyboard component of Google Chrome, specifically on Chrome OS. This could allow a local attacker, with physical access to the device, to bypass navigation restrictions. The exploitation of this issue may impact the confidentiality, integrity, and availability of protected information through a specially crafted web page.
Recommendations For versions prior to 100.0.4896.60, update to version 100.0.4896.60 or later to resolve the issue. As a temporary workaround, consider restricting physical access to devices to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1610
ALT-PU-2022-1638
ALT-PU-2022-1681
ALT-PU-2022-2055
BDU:2022-01920
CVE-2022-1132
DSA-5112-1
MGASA-2022-0130
OPENSUSE-SU-2022_0112-1
OPENSUSE-SU-2024:11967-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Google Chrome
Suse