MEDIUM
CVE-2022-2856
CVSS
6.5
KEV
Description
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
Summary dbcve.org
Insufficient validation of untrusted input in Android Intents in Google Chrome on Android prior to version 104.0.5112.101 allows a remote attacker to bypass intent validation through a crafted HTML page, enabling arbitrary navigation to malicious websites.
Mitigation
Update Google Chrome for Android to version 104.0.5112.101 or later to address the insufficient input validation vulnerability in Intents.
Weakness (CWE)
CWE-20
Improper Input Validation
EPSS Score
4.53%
Probability of exploitation in next 30 days
91.2th percentile
References
https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html
Patch, Release Notes, Vendor Advisory
https://crbug.com/1345630
Exploit, Issue Tracking, Mailing List, Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-2856
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.