First published: Thu Oct 21 2021(Updated: )
Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Credit: Luan Herrera @lbherrera_ chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <100.0.4896.88 | 100.0.4896.88 |
Google Chrome (Trace Event) | <100.0.4896.88 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-1307 has been classified as a high-severity vulnerability due to its potential impact on the integrity of the URL bar in Google Chrome on Android.
To fix CVE-2022-1307, update Google Chrome on Android to version 100.0.4896.88 or later.
CVE-2022-1307 affects users of Google Chrome on Android versions prior to 100.0.4896.88.
CVE-2022-1307 can be exploited by remote attackers to spoof the contents of the Omnibox through crafted HTML pages.
CVE-2022-1307 was publicly disclosed in April 2022 when the corresponding update was issued.