CVE-2022-2164: Inappropriate implementation in Extensions API
Inappropriate implementation in Extensions API in Google Chrome prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-2164?
CVE-2022-2164 has a high severity rating due to potential unauthorized access via malicious Chrome extensions.
How do I fix CVE-2022-2164?
To mitigate CVE-2022-2164, upgrade Google Chrome to version 103.0.5060.53 or later.
What versions of Google Chrome are affected by CVE-2022-2164?
CVE-2022-2164 affects Google Chrome versions prior to 103.0.5060.53.
Can CVE-2022-2164 affect my Fedora system?
Yes, CVE-2022-2164 can impact Fedora 35 and 36 users if they use the affected version of Google Chrome.
What should I do if I have installed a malicious extension related to CVE-2022-2164?
If you suspect a malicious extension related to CVE-2022-2164, remove it immediately and update your Chrome browser.