PT-2023-4307 · Google+1 · Google Chrome+1
Thomas Orlita
·
Published
2022-07-22
·
Updated
2023-08-19
·
CVE-2022-4915
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 103.0.5060.134
Description
The issue is related to an inappropriate implementation in URL formatting, which can be exploited by a remote attacker to perform domain spoofing via a crafted HTML page. This can be achieved by manipulating the URL formatting mechanism, allowing the attacker to deceive users about the actual domain they are interacting with.
Recommendations
For Google Chrome versions prior to 103.0.5060.134, update to version 103.0.5060.134 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable web pages or avoiding the use of HTML pages from untrusted sources until the update is applied.
Exploit
Fix
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Google Chrome