CVE-2022-3057: Inappropriate implementation in iframe Sandbox
Published Jun 16, 2022
·Updated
Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Credit
Gareth Heyes
Affected Software
3 affected componentsFixes available
Google Chrome<105.0.5195.52
105.0.5195.52
Google Chrome<105.0.5195.52
fedoraproject fedora=37
Remediation
Event History
Jun 16, 2022
CVE Published
12:00 AM
Sep 26, 2022
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-3057?
CVE-2022-3057 has a medium severity level due to its potential to leak cross-origin data.
2
How do I fix CVE-2022-3057?
To fix CVE-2022-3057, upgrade Google Chrome to version 105.0.5195.52 or later.
3
Which versions of Google Chrome are affected by CVE-2022-3057?
Google Chrome versions prior to 105.0.5195.52 are affected by CVE-2022-3057.
4
Can CVE-2022-3057 affect users on Fedora systems?
Yes, CVE-2022-3057 can affect users running Fedora 37 that use vulnerable versions of Google Chrome.
5
What type of attack can CVE-2022-3057 enable?
CVE-2022-3057 allows remote attackers to leak cross-origin data via a crafted HTML page.