CVE-2022-0291: Inappropriate implementation in Storage
Published Dec 19, 2021
·Updated
Inappropriate implementation in Storage in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Credit
Anonymous
Affected Software
2 affected componentsFixes available
Google Chrome<97.0.4692.99
97.0.4692.99
Google Chrome<97.0.4692.99
Event History
Dec 19, 2021
CVE Published
12:00 AM
Feb 12, 2022
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0291?
CVE-2022-0291 is classified as a high severity vulnerability that can allow attackers to bypass site isolation in Google Chrome.
2
How do I fix CVE-2022-0291?
To fix CVE-2022-0291, update Google Chrome to version 97.0.4692.99 or later.
3
What kind of attack does CVE-2022-0291 facilitate?
CVE-2022-0291 facilitates attacks where a remote attacker can exploit the renderer process to bypass security mechanisms.
4
Which versions of Google Chrome are affected by CVE-2022-0291?
CVE-2022-0291 affects Google Chrome versions prior to 97.0.4692.99.
5
Who is the vendor responsible for addressing CVE-2022-0291?
Google is the vendor responsible for addressing CVE-2022-0291 in their Chrome browser.