CVE-2022-1495: Incorrect security UI in Downloads
Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-1477
- CVE-2022-1478
- CVE-2022-1479
- CVE-2022-4920
- CVE-2022-1481
- CVE-2022-1919
- CVE-2022-4919
- CVE-2022-1482
- CVE-2022-1483
- CVE-2022-1484
- CVE-2022-1485
- CVE-2022-1486
- CVE-2022-1487
- CVE-2022-1488
- CVE-2022-1489
- CVE-2022-1490
- CVE-2022-1491
- CVE-2022-1492
- CVE-2022-1493
- CVE-2022-1494
- CVE-2022-1496
- CVE-2022-1497
- CVE-2022-1498
- CVE-2022-1499
- CVE-2022-1500
- CVE-2022-1501
Frequently Asked Questions
What is the severity of CVE-2022-1495?
CVE-2022-1495 is classified as a high severity vulnerability due to its potential to allow remote spoofing of APK download dialogs.
How do I fix CVE-2022-1495?
To fix CVE-2022-1495, users should update Google Chrome to version 101.0.4951.41 or later.
What platforms are affected by CVE-2022-1495?
CVE-2022-1495 affects the Google Chrome browser running on Android devices prior to version 101.0.4951.41.
What type of vulnerability is CVE-2022-1495?
CVE-2022-1495 is an incorrect security UI vulnerability concerning the Downloads feature in Google Chrome.
Can CVE-2022-1495 be exploited remotely?
Yes, CVE-2022-1495 can be exploited remotely by a malicious actor using a crafted HTML page to spoof the APK downloads dialog.