CVE-2022-1130NULL Pointer Dereference in Google Chrome

Severity
8.1HIGHNVD
CISA7.8
EPSS
0.5%
top 33.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateJul 24

Description

Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to send arbitrary intents from any app via a malicious app.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages6 packages

CVEListV5google/chromeunspecified100.0.4896.60
NVDgoogle/chrome< 100.0.4896.60
debiandebian/chromium< chromium 100.0.4896.60-1 (bookworm)
Debianchromium/chromium< 100.0.4896.60-1~deb11u1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9wq5-2p9c-q5w5: Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 1002022-07-24
OSV
CVE-2022-1130: Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 1002022-07-23

📋Vendor Advisories

5
CISA
Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability2022-05-23
Microsoft
Chromium: CVE-2022-1130 Insufficient validation of untrusted input in WebOTP2022-04-12
Chrome
Stable Channel Update for Desktop: CVE-2022-11292022-03-29
CISA
Apple OS X Authentication Bypass Vulnerability2022-02-10
Debian
CVE-2022-1130: chromium - Insufficient validation of trust input in WebOTP in Google Chrome on Android pri...2022