CVE-2022-1129 — Authentication Bypass by Spoofing in Google Chrome
Severity
6.5MEDIUMNVD
CISA7.8
EPSS
0.2%
top 61.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateJul 24
Description
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages6 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
4CISA
▶
Debian▶
CVE-2022-1129: chromium - Inappropriate implementation in Full Screen Mode in Google Chrome on Android pri...↗2022