First published: Sun Jan 23 2022(Updated: )
Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Credit: chrome-cve-admin@google.com chrome-cve-admin@google.com Sohom Datta
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <100.0.4896.60 | |
Google Chrome | <100.0.4896.60 | 100.0.4896.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-1146 has been rated as a high severity vulnerability.
To fix CVE-2022-1146, update Google Chrome to version 100.0.4896.60 or later.
CVE-2022-1146 allows a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2022-1146 affects Google Chrome versions prior to 100.0.4896.60.
There are no known workarounds for CVE-2022-1146; updating the browser is the recommended course of action.