PT-2022-2482 · Google+2 · Google Chrome+2

Alesandro Ortiz

+1

·

Published

2022-05-10

·

Updated

2024-06-15

·

CVE-2022-1637

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 101.0.4951.64
Description The issue is caused by an inappropriate implementation in Web Contents, allowing a remote attacker to leak cross-origin data via a crafted HTML page. This is due to insufficient input validation in the Web Contents component. The exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations For Google Chrome versions prior to 101.0.4951.64, update to version 101.0.4951.64 or later to resolve the issue.

Fix

RCE

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02892
CVE-2022-1637
DSA-5134-1
MGASA-2022-0188
OPENSUSE-SU-2022:0133-1
OPENSUSE-SU-2022:0147-1
OPENSUSE-SU-2022:0156-1
OPENSUSE-SU-2022_0147-1
OPENSUSE-SU-2022_0156-1
OPENSUSE-SU-2024:12061-1
OPENSUSE-SU-2024:12093-1
OPENSUSE-SU-2024:12948-1

Affected Products

Astra Linux
Google Chrome
Suse