CVE-2022-1488: Inappropriate implementation in Extensions API
Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-1477
- CVE-2022-1478
- CVE-2022-1479
- CVE-2022-4920
- CVE-2022-1481
- CVE-2022-1919
- CVE-2022-4919
- CVE-2022-1482
- CVE-2022-1483
- CVE-2022-1484
- CVE-2022-1485
- CVE-2022-1486
- CVE-2022-1487
- CVE-2022-1489
- CVE-2022-1490
- CVE-2022-1491
- CVE-2022-1492
- CVE-2022-1493
- CVE-2022-1494
- CVE-2022-1495
- CVE-2022-1496
- CVE-2022-1497
- CVE-2022-1498
- CVE-2022-1499
- CVE-2022-1500
- CVE-2022-1501
Frequently Asked Questions
What is the severity of CVE-2022-1488?
CVE-2022-1488 is considered a high-severity vulnerability due to its potential for data leakage through malicious Chrome extensions.
How do I fix CVE-2022-1488?
To fix CVE-2022-1488, users should upgrade to Google Chrome version 101.0.4951.41 or later.
What types of attacks can CVE-2022-1488 facilitate?
CVE-2022-1488 can facilitate attacks that lead to the leakage of cross-origin data through malicious Chrome extensions.
Who is affected by CVE-2022-1488?
Users of Google Chrome versions prior to 101.0.4951.41 are affected by CVE-2022-1488.
What is the nature of the vulnerability in CVE-2022-1488?
CVE-2022-1488 involves an inappropriate implementation in the Extensions API of Google Chrome.