PT-2022-6777 · Google+1 · Google Chrome+1

Published

2022-03-01

·

Updated

2023-08-12

·

CVE-2022-4923

CVSS v2.0

3.6

Low

VectorAV:N/AC:H/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 99.0.4844.51
Description The issue is related to an inappropriate implementation in the Omnibox feature of Google Chrome, which could allow an attacker in a privileged network position to perform a man-in-the-middle attack via malicious network traffic. This could potentially enable the attacker to intercept and manipulate sensitive data.
Recommendations For Google Chrome versions prior to 99.0.4844.51, update to version 99.0.4844.51 or later to resolve the issue. As a temporary workaround, consider restricting network access to minimize the risk of exploitation.

Exploit

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04630
CVE-2022-4923
DSA-5089-1

Affected Products

Astra Linux
Google Chrome