PT-2023-4137 · Google · Google Chrome

Axel Chong

·

Published

2023-01-26

·

Updated

2024-10-29

·

CVE-2022-4926

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome on Android versions prior to 109.0.5414.119
Description The issue is related to insufficient policy enforcement in Intents, allowing a remote attacker to bypass the same origin policy via a crafted HTML page. This could potentially enable the attacker to circumvent existing security restrictions.
Recommendations For Google Chrome on Android versions prior to 109.0.5414.119, update to version 109.0.5414.119 or later to resolve the issue. As a temporary workaround, consider restricting the use of Intents in Google Chrome on Android until a patch is applied.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2023-04446
CVE-2022-4926
DSA-5328-1

Affected Products

Google Chrome