CVE-2022-3048
published 2022-09-26CVE-2022-3048: Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen…
PriorityP425medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.38%
29.9th percentile
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 105.0.5195.52-1~deb11u1 | 105.0.5195.52-1~deb11u1 |
| chromium | chromium | >= 0 < 105.0.5195.52-1 | 105.0.5195.52-1 |
| chromium | chromium | >= 0 < 105.0.5195.52-1 | 105.0.5195.52-1 |
| chromium | chromium | >= 0 < 105.0.5195.52-1 | 105.0.5195.52-1 |
| debian | chromium | < chromium 105.0.5195.52-1 (bookworm) | chromium 105.0.5195.52-1 (bookworm) |
| fedoraproject | fedora | — | — |
| chrome | < 105.0.5195.52 | 105.0.5195.52 | |
| chrome | >= unspecified < 105.0.5195.52 | 105.0.5195.52 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2022-3047
vendor_chrome·2022-08-30·CVSS 6.5
CVE-2022-3047 [MEDIUM] Stable Channel Update for Desktop: CVE-2022-3047
Stable Channel Update for Desktop
CVE-2022-3047: Insufficient policy enforcement in Extensions API. Reported by Maurice Dauer on 2022-07-07 [$5000][ 1303308 ] Medium CVE-2022-3048: Inappropriate implementation in Chrome OS lockscreen
Reported by Andr
Severity: medium
Debian
CVE-2022-3048: chromium - Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome ...
vendor_debian·2022·CVSS 6.8
CVE-2022-3048 [MEDIUM] CVE-2022-3048: chromium - Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome ...
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (fixed in 105.0.5195.52-1)
sid: resolved (fixed in 105.0.5195.52-1)
trixie: resolved (fixed in 105.0.5195.52-1)
GHSA
GHSA-938g-35m6-qcp8: Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105
ghsa_unreviewed·2022-09-27
CVE-2022-3048 [MEDIUM] CWE-862 GHSA-938g-35m6-qcp8: Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
OSV
CVE-2022-3048: Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105
osv·2022-09-26·CVSS 6.8
CVE-2022-3048 [MEDIUM] CVE-2022-3048: Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_30.htmlhttps://crbug.com/1303308https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/https://security.gentoo.org/glsa/202209-23https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_30.htmlhttps://crbug.com/1303308https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/https://security.gentoo.org/glsa/202209-23
2022-09-26
Published