CVE-2022-2856: Insufficient validation of untrusted input in Intents
Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 104.0.5112.101
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-2856?
CVE-2022-2856 has been classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2022-2856?
To fix CVE-2022-2856, update Google Chrome to version 104.0.5112.101 or later.
Which software is affected by CVE-2022-2856?
CVE-2022-2856 affects Google Chrome versions prior to 104.0.5112.101 and may impact other Chromium-based browsers.
Can CVE-2022-2856 be exploited remotely?
Yes, CVE-2022-2856 can be exploited remotely by tricking users into visiting a malicious website.
What are the consequences of CVE-2022-2856?
If exploited, CVE-2022-2856 could allow attackers to gain unauthorized access or perform malicious actions on a user's device.