CVE-2022-2622Improper Input Validation in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 39.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateAug 13

Description

Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5google/chromeunspecified104.0.5112.79
NVDgoogle/chrome< 104.0.5112.79
debiandebian/chromium< chromium 104.0.5112.79-1 (bookworm)
Debianchromium/chromium< 104.0.5112.79-1~deb11u1+3

Also affects: Fedora 37

🔴Vulnerability Details

2
GHSA
GHSA-4x87-928j-5x8q: Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 1042022-08-13
OSV
CVE-2022-2622: Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 1042022-08-12

📋Vendor Advisories

2
Microsoft
Chromium: CVE-2022-2622 Insufficient validation of untrusted input in Safe Browsing2022-08-09
Debian
CVE-2022-2622: chromium - Insufficient validation of untrusted input in Safe Browsing in Google Chrome on ...2022