PT-2022-4489 · Google+2 · Google Chrome+2

Irvan Kurniawan

+1

·

Published

2022-08-05

·

Updated

2024-06-15

·

CVE-2022-2611

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 104.0.5112.79 Microsoft Edge (affected versions not specified)
Description The issue is related to an inappropriate implementation of the Fullscreen API in Google Chrome and Microsoft Edge browsers. This could allow a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page, potentially revealing protected information.
Recommendations For Google Chrome versions prior to 104.0.5112.79, update to version 104.0.5112.79 or later to resolve the issue. For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05356
CVE-2022-2611
DSA-5201-1
MGASA-2022-0277
OPENSUSE-SU-2022:10086-1
OPENSUSE-SU-2022:10092-1
OPENSUSE-SU-2024:12251-1
OPENSUSE-SU-2024:12948-1

Affected Products

Astra Linux
Google Chrome
Edge