PT-2022-4287 · Google+3 · Google Chrome+4
Ashley Shen
+1
·
Published
2022-07-19
·
Updated
2025-10-24
·
CVE-2022-2856
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 104.0.5112.101
Microsoft Edge (affected versions not specified)
Description
The issue is related to insufficient validation of untrusted input in Intents, allowing a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page. This can lead to the execution of arbitrary code. The vulnerability has been exploited in the wild, with reports of its use in targeted attacks. Google has updated Chrome to version 104, which fixes this vulnerability along with 10 others. The new version of Android, Android 13, has also introduced security features that limit the capabilities of mobile malware, but researchers have already found ways to bypass these restrictions.
Recommendations
For Google Chrome versions prior to 104.0.5112.101, update to version 104.0.5112.101 or later to fix the vulnerability.
For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Astra Linux
Google Chrome
Edge
Suse