CVE-2022-0097Google Chrome vulnerability

5 documents5 sources
Severity
9.6CRITICALNVD
EPSS
0.3%
top 48.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateFeb 13

Description

Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0

Affected Packages5 packages

CVEListV5google/chromeunspecified97.0.4692.71
NVDgoogle/chrome< 97.0.4692.71
debiandebian/chromium< chromium 97.0.4692.71-0.1 (bookworm)
Debianchromium/chromium< 97.0.4692.71-0.1~deb11u1+3

Also affects: Fedora 34, 35, 36

🔴Vulnerability Details

2
GHSA
GHSA-r8vm-x84f-276c: Inappropriate implementation in DevTools in Google Chrome prior to 972022-02-13
OSV
CVE-2022-0097: Inappropriate implementation in DevTools in Google Chrome prior to 972022-02-12

📋Vendor Advisories

2
Microsoft
Chromium: CVE-2022-0097 Inappropriate implementation in DevTools2022-01-11
Debian
CVE-2022-0097: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 ...2022