CVE-2022-4025
published 2023-01-02CVE-2022-4025: Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a…
PriorityP417medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.46%
37.5th percentile
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 98.0.4758.80-1~deb11u1 | 98.0.4758.80-1~deb11u1 |
| chromium | chromium | >= 0 < 98.0.4758.80-1 | 98.0.4758.80-1 |
| chromium | chromium | >= 0 < 98.0.4758.80-1 | 98.0.4758.80-1 |
| chromium | chromium | >= 0 < 98.0.4758.80-1 | 98.0.4758.80-1 |
| debian | chromium | < chromium 98.0.4758.80-1 (bookworm) | chromium 98.0.4758.80-1 (bookworm) |
| chrome | < 98.0.4758.80 | 98.0.4758.80 | |
| chrome | >= unspecified < 98.0.4758.80 | 98.0.4758.80 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2022-4025
vendor_chrome·2022-02-01·CVSS 4.3
CVE-2022-4025 [LOW] Stable Channel Update for Desktop: CVE-2022-4025
Stable Channel Update for Desktop
CVE-2022-4025: Inappropriate implementation in Paint. Reported by Suhwan Song on 2021-10-15 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel
Severity: low
Debian
CVE-2022-4025: chromium - Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 all...
vendor_debian·2022·CVSS 4.3
CVE-2022-4025 [MEDIUM] CVE-2022-4025: chromium - Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 all...
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resolved (fixed in 98.0.4758.80-1)
trixie: resolved (fixed in 98.0.4758.80-1)
GHSA
GHSA-wv48-pvf9-qv86: Inappropriate implementation in Paint in Google Chrome prior to 98
ghsa_unreviewed·2023-01-03
CVE-2022-4025 [MEDIUM] CWE-203 GHSA-wv48-pvf9-qv86: Inappropriate implementation in Paint in Google Chrome prior to 98
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
OSV
CVE-2022-4025: Inappropriate implementation in Paint in Google Chrome prior to 98
osv·2023-01-02·CVSS 4.3
CVE-2022-4025 [MEDIUM] CVE-2022-4025: Inappropriate implementation in Paint in Google Chrome prior to 98
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-02
Published