PT-2022-25304 · Google+2 · Google Chrome+2

Suhwan Song

·

Published

2022-02-01

·

Updated

2024-10-29

·

CVE-2022-4025

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 98.0.4758.80
Description The issue is related to an inappropriate implementation in Paint, allowing a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. This can be achieved by exploiting the vulnerability in Google Chrome.
Recommendations For Google Chrome versions prior to 98.0.4758.80, update to version 98.0.4758.80 or later to resolve the issue.

Exploit

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1216
ALT-PU-2022-1323
ALT-PU-2022-1681
ALT-PU-2022-2055
CVE-2022-4025
DSA-5068-1

Affected Products

Alt Linux
Astra Linux
Google Chrome