CVE-2022-2479: Insufficient validation of untrusted input in File
Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-2479?
CVE-2022-2479 is considered a high severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2022-2479?
To fix CVE-2022-2479, update Google Chrome to version 103.0.5060.134 or later.
What does CVE-2022-2479 affect?
CVE-2022-2479 affects Google Chrome on Android versions prior to 103.0.5060.134.
What type of attack is associated with CVE-2022-2479?
CVE-2022-2479 can be exploited by attackers via a crafted HTML page to access internal file directories.
Is my device vulnerable to CVE-2022-2479?
If you are using a version of Google Chrome on Android earlier than 103.0.5060.134, your device is vulnerable to CVE-2022-2479.