CVE-2022-1129Authentication Bypass by Spoofing in Google Chrome

Severity
6.5MEDIUMNVD
CISA7.8
EPSS
0.2%
top 61.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateJul 24

Description

Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5google/chromeunspecified100.0.4896.60
NVDgoogle/chrome< 100.0.4896.60
debiandebian/chromium< chromium 100.0.4896.60-1 (bookworm)
Debianchromium/chromium< 100.0.4896.60-1~deb11u1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j9gm-f3p3-j5g3: Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 1002022-07-24
OSV
CVE-2022-1129: Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 1002022-07-23

📋Vendor Advisories

4
Microsoft
Chromium: CVE-2022-1129 Inappropriate implementation in Full Screen Mode2022-04-12
Chrome
Stable Channel Update for Desktop: CVE-2022-11292022-03-29
CISA
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability2022-03-15
Debian
CVE-2022-1129: chromium - Inappropriate implementation in Full Screen Mode in Google Chrome on Android pri...2022