CVE-2022-0466: Inappropriate implementation in Extensions Platform
Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-0466?
CVE-2022-0466 has a high severity rating due to its potential for sandbox escape via malicious extensions.
How do I fix CVE-2022-0466?
To fix CVE-2022-0466, update Google Chrome to version 98.0.4758.80 or later.
What type of attack does CVE-2022-0466 enable?
CVE-2022-0466 enables attackers to perform a sandbox escape through a crafted HTML page when a malicious extension is installed.
Which versions of Google Chrome are affected by CVE-2022-0466?
CVE-2022-0466 affects Google Chrome versions prior to 98.0.4758.80.
Can CVE-2022-0466 be exploited remotely?
Yes, CVE-2022-0466 can be exploited remotely if a user unknowingly installs a malicious extension.