CVE-2022-0804: Inappropriate implementation in Full screen mode
Published Oct 29, 2021
·Updated
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.
Credit
Irvan Kurniawan (sourc7)
Affected Software
6 affected componentsFixes available
Google Chrome<99.0.4844.51
99.0.4844.51
Google Chrome<99.0.4844.51
Apple macOS
Google Android
Linux Linux Kernel
Microsoft Windows
Event History
Oct 29, 2021
CVE Published
12:00 AM
Apr 5, 2022
CVE Published
via MITRE·12:25 AM
Data Sourced
via MITRE·12:25 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-0804?
CVE-2022-0804 has a medium-level severity due to the potential exposure of the Omnibox contents to remote attackers.
2
How do I fix CVE-2022-0804?
To fix CVE-2022-0804, upgrade to Google Chrome version 99.0.4844.51 or later.
3
Which versions of Google Chrome are affected by CVE-2022-0804?
CVE-2022-0804 affects Google Chrome versions prior to 99.0.4844.51.
4
What does CVE-2022-0804 exploit?
CVE-2022-0804 exploits an inappropriate implementation in Full screen mode on Google Chrome for Android.
5
Can I use Google Chrome on Android without risk after the fix for CVE-2022-0804?
Yes, after updating to version 99.0.4844.51 or later, the risk associated with CVE-2022-0804 is mitigated.