CVE-2022-0455: Inappropriate implementation in Full Screen Mode
Published Nov 16, 2021
·Updated
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Credit
Irvan Kurniawan (sourc7)
Affected Software
3 affected componentsFixes available
Google Chrome<98.0.4758.80
98.0.4758.80
Google Chrome<98.0.4758.80
Google Android
Event History
Nov 16, 2021
CVE Published
12:00 AM
Apr 5, 2022
CVE Published
via MITRE·12:51 AM
Data Sourced
via MITRE·12:51 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-0455.
2
What is the severity of CVE-2022-0455?
The severity of CVE-2022-0455 is medium with a CVSS score of 6.5.
3
What software versions are affected by CVE-2022-0455?
Google Chrome on Android prior to version 98.0.4758.80 is affected by CVE-2022-0455.
4
How can a remote attacker exploit CVE-2022-0455?
A remote attacker can exploit CVE-2022-0455 by spoofing the contents of the Omnibox (URL bar) via a crafted HTML page.
5
Is Google Android affected by CVE-2022-0455?
No, Google Android is not affected by CVE-2022-0455.
6
How do I fix CVE-2022-0455?
To fix CVE-2022-0455, update Google Chrome on Android to version 98.0.4758.80 or later.