MEDIUM

CVE-2022-2856

Google Chrome 2022-09-26 CVSS v3.1
CVSS
6.5
KEV

Description

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

Summary dbcve.org

Insufficient validation of untrusted input in Android Intents in Google Chrome on Android prior to version 104.0.5112.101 allows a remote attacker to bypass intent validation through a crafted HTML page, enabling arbitrary navigation to malicious websites.

Mitigation

Update Google Chrome for Android to version 104.0.5112.101 or later to address the insufficient input validation vulnerability in Intents.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

4.53%
Probability of exploitation in next 30 days
91.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE