PT-2022-6777 · Google+1 · Google Chrome+1
Published
2022-03-01
·
Updated
2023-08-12
·
CVE-2022-4923
CVSS v2.0
3.6
Low
| Vector | AV:N/AC:H/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 99.0.4844.51
Description
The issue is related to an inappropriate implementation in the Omnibox feature of Google Chrome, which could allow an attacker in a privileged network position to perform a man-in-the-middle attack via malicious network traffic. This could potentially enable the attacker to intercept and manipulate sensitive data.
Recommendations
For Google Chrome versions prior to 99.0.4844.51, update to version 99.0.4844.51 or later to resolve the issue. As a temporary workaround, consider restricting network access to minimize the risk of exploitation.
Exploit
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Google Chrome