CVE-2022-2860: Insufficient policy enforcement in Cookies
Published Jul 18, 2022
·Updated
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page.
Credit
Axel Chong
Affected Software
3 affected componentsFixes available
Google Chrome<104.0.5112.101
104.0.5112.101
Google Chrome<104.0.5112.101
fedoraproject fedora=37
Remediation
Event History
Jul 18, 2022
CVE Published
12:00 AM
Sep 26, 2022
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-2860?
CVE-2022-2860 is classified as a high severity vulnerability.
2
How do I fix CVE-2022-2860?
To fix CVE-2022-2860, update Google Chrome to version 104.0.5112.101 or later.
3
Who is affected by CVE-2022-2860?
Users of Google Chrome prior to version 104.0.5112.101 and Fedora 37 are affected by CVE-2022-2860.
4
What does CVE-2022-2860 exploit?
CVE-2022-2860 exploits insufficient policy enforcement in cookie handling in Google Chrome.
5
Can CVE-2022-2860 lead to data breaches?
Yes, CVE-2022-2860 could potentially allow attackers to bypass cookie prefix restrictions, which might lead to unauthorized access to user data.