CVE-2022-1130 — NULL Pointer Dereference in Google Chrome
Severity
8.1HIGHNVD
CISA7.8
EPSS
0.5%
top 33.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateJul 24
Description
Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to send arbitrary intents from any app via a malicious app.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2
Affected Packages6 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
5Debian▶
CVE-2022-1130: chromium - Insufficient validation of trust input in WebOTP in Google Chrome on Android pri...↗2022