CVE-2022-4189Google Chrome vulnerability

9 documents6 sources
Severity
4.3MEDIUMNVD
OSV5.7OSV5.3
EPSS
0.1%
top 82.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateDec 13

Description

Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages6 packages

CVEListV5google/chromeunspecified108.0.5359.71
NVDgoogle/chrome< 108.0.5359.71
debiandebian/chromium< chromium 108.0.5359.71-1 (bookworm)
Debianchromium/chromium< 108.0.5359.71-2~deb11u1+3

🔴Vulnerability Details

5
GHSA
GHSA-mmq8-6g35-x65g: Insufficient policy enforcement in DevTools in Google Chrome prior to 1082022-11-30
OSV
CVE-2022-4189: Insufficient policy enforcement in DevTools in Google Chrome prior to 1082022-11-30
OSV
python2.7 vulnerabilities2022-08-24
OSV
python3.7 vulnerability2022-05-23
OSV
python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities2022-03-28

📋Vendor Advisories

3
Microsoft
Chromium: CVE-2022-4189 Insufficient policy enforcement in DevTools2022-12-13
Chrome
Stable Channel Update for Desktop: CVE-2022-41892022-11-29
Debian
CVE-2022-4189: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359...2022