First published: Thu Mar 10 2022(Updated: )
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee WebAdvisor | <=8.1.0.1895 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0815 is an improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895.
The severity of CVE-2022-0815 is high with a CVSS score of 7.3.
CVE-2022-0815 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system.
If affected by CVE-2022-0815, unexpected behaviors can occur including settings being changed.
To fix CVE-2022-0815, update your McAfee WebAdvisor Chrome and Edge browser extensions to version 8.1.0.1896 or later.