First published: Sat May 28 2022(Updated: )
Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a crafted HTML page.
Credit: chrome-cve-admin@google.com anonymous
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <103.0.5060.134 | 103.0.5060.134 |
Google Chrome (Trace Event) | <103.0.5060.134 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-2479 is considered a high severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2022-2479, update Google Chrome to version 103.0.5060.134 or later.
CVE-2022-2479 affects Google Chrome on Android versions prior to 103.0.5060.134.
CVE-2022-2479 can be exploited by attackers via a crafted HTML page to access internal file directories.
If you are using a version of Google Chrome on Android earlier than 103.0.5060.134, your device is vulnerable to CVE-2022-2479.