CVE-2022-2479Improper Input Validation in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 61.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 28
Latest updateAug 10

Description

Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages6 packages

CVEListV5google/chromeunspecified103.0.5060.134
NVDgoogle/chrome< 103.0.5060.134
debiandebian/chromium< chromium 103.0.5060.134-1 (bookworm)
Debianchromium/chromium< 103.0.5060.134-1~deb11u1+3

🔴Vulnerability Details

2
GHSA
GHSA-pmv2-vq2x-c74g: Insufficient validation of untrusted input in File in Google Chrome on Android prior to 1032022-07-29
OSV
CVE-2022-2479: Insufficient validation of untrusted input in File in Google Chrome on Android prior to 1032022-07-28

📋Vendor Advisories

3
Chrome
Long Term Support Candidate Channel Update for ChromeOS: CVE-2022-24792022-08-10
Microsoft
Chromium: CVE-2022-2479 Insufficient validation of untrusted input in File2022-07-12
Debian
CVE-2022-2479: chromium - Insufficient validation of untrusted input in File in Google Chrome on Android p...2022