CVE-2022-3312
published 2022-11-01CVE-2022-3312: Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device…
PriorityP416medium4.6CVSS 3.1
AVPACLPRNUINSUCNIHAN
EPSS
0.23%
14.2th percentile
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 106.0.5249.61-1~deb11u1 | 106.0.5249.61-1~deb11u1 |
| chromium | chromium | >= 0 < 106.0.5249.61-1 | 106.0.5249.61-1 |
| chromium | chromium | >= 0 < 106.0.5249.61-1 | 106.0.5249.61-1 |
| chromium | chromium | >= 0 < 106.0.5249.61-1 | 106.0.5249.61-1 |
| debian | chromium | < chromium 106.0.5249.61-1 (bookworm) | chromium 106.0.5249.61-1 (bookworm) |
| chrome | < 106.0.5249.62 | 106.0.5249.62 | |
| chrome | >= unspecified < 106.0.5249.62 | 106.0.5249.62 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv4.6MEDIUM
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vvw2-cwrq-mprr: Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106
ghsa_unreviewed·2022-11-02
CVE-2022-3312 [MEDIUM] CWE-20 GHSA-vvw2-cwrq-mprr: Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chrome security severity: Medium)
OSV
CVE-2022-3312: Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106
osv·2022-11-01·CVSS 4.6
CVE-2022-3312 [MEDIUM] CVE-2022-3312: Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)
Chrome
Stable Channel Update for Desktop: CVE-2022-3311
vendor_chrome·2022-09-27·CVSS 6.5
CVE-2022-3311 [MEDIUM] Stable Channel Update for Desktop: CVE-2022-3311
Stable Channel Update for Desktop
CVE-2022-3311: Use after free in Import. Reported by Samet Bekmezci @sametbekmezci on 2022-03-04 [$TBD][ 1303306 ] Medium CVE-2022-3312: Insufficient validation of untrusted input in VPN
Reported by Andr
Severity: medium
Debian
CVE-2022-3312: chromium - Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS p...
vendor_debian·2022·CVSS 4.6
CVE-2022-3312 [MEDIUM] CVE-2022-3312: chromium - Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS p...
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (fixed in 106.0.5249.61-1)
sid: resolved (fixed in 106.0.5249.61-1)
trixie: resolved (fixed in 106.0.5249.61-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-01
Published