PT-2022-4287 · Google+3 · Google Chrome+4

Ashley Shen

+1

·

Published

2022-07-19

·

Updated

2025-10-24

·

CVE-2022-2856

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 104.0.5112.101 Microsoft Edge (affected versions not specified)
Description The issue is related to insufficient validation of untrusted input in Intents, allowing a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page. This can lead to the execution of arbitrary code. The vulnerability has been exploited in the wild, with reports of its use in targeted attacks. Google has updated Chrome to version 104, which fixes this vulnerability along with 10 others. The new version of Android, Android 13, has also introduced security features that limit the capabilities of mobile malware, but researchers have already found ways to bypass these restrictions.
Recommendations For Google Chrome versions prior to 104.0.5112.101, update to version 104.0.5112.101 or later to fix the vulnerability. For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05141
CVE-2022-2856
DSA-5212-1
MGASA-2022-0307
OPENSUSE-SU-2022:10099-1
OPENSUSE-SU-2022:10108-1
OPENSUSE-SU-2022:10109-1
OPENSUSE-SU-2022_10108-1
OPENSUSE-SU-2022_10109-1
OPENSUSE-SU-2024:12277-1
OPENSUSE-SU-2024:12948-1

Affected Products

Android
Astra Linux
Google Chrome
Edge
Suse