CVE-2022-1306: Inappropriate implementation in compositing
Published Feb 21, 2022
·Updated
Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Credit
Sven Dysthe
Affected Software
2 affected componentsFixes available
Google Chrome<100.0.4896.88
100.0.4896.88
Google Chrome<100.0.4896.88
Remediation
Patch Available
Event History
Feb 21, 2022
CVE Published
12:00 AM
Jul 25, 2022
CVE Published
via MITRE·01:39 PM
Data Sourced
via MITRE·01:39 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-1306?
CVE-2022-1306 has a severity rating that indicates it allows remote attackers to spoof the contents of the Omnibox in Google Chrome.
2
How do I fix CVE-2022-1306?
To fix CVE-2022-1306, upgrade to Google Chrome version 100.0.4896.88 or later.
3
What versions of Google Chrome are affected by CVE-2022-1306?
CVE-2022-1306 affects Google Chrome versions prior to 100.0.4896.88.
4
What type of vulnerability is CVE-2022-1306?
CVE-2022-1306 is classified as an issue with inappropriate implementation in compositing.
5
Can CVE-2022-1306 be exploited by an attacker?
Yes, CVE-2022-1306 can be exploited by a remote attacker through a crafted HTML page.