First published: Sat Jan 22 2022(Updated: )
Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page.
Credit: chrome-cve-admin@google.com Thomas Orlita
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <100.0.4896.60 | |
Google Chrome | <100.0.4896.60 | 100.0.4896.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-1137 is classified as a high-severity vulnerability due to its potential for information leakage.
To fix CVE-2022-1137, update Google Chrome to version 100.0.4896.60 or later.
CVE-2022-1137 exploits inappropriate implementation in Extensions in Google Chrome allowing information leakage.
Users of Google Chrome versions prior to 100.0.4896.60 may be affected by CVE-2022-1137.
An attacker can potentially leak sensitive information by convincing a user to install a malicious extension.