CVE-2022-3201: Insufficient validation of untrusted input in Developer Tools
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-3201?
CVE-2022-3201 is a vulnerability in DevTools in Google Chrome on Chrome OS prior to version 105.0.5195.125.
What is the severity of CVE-2022-3201?
The severity of CVE-2022-3201 is Medium with a score of 5.4 (out of 10).
How does CVE-2022-3201 allow an attacker to bypass navigation restrictions?
CVE-2022-3201 allows an attacker who convinced a user to install a malicious extension to bypass navigation restrictions through a crafted HTML page.
Which software versions are affected by CVE-2022-3201?
Google Chrome on Chrome OS prior to version 105.0.5195.125 is affected by CVE-2022-3201.
How can I fix CVE-2022-3201?
To fix CVE-2022-3201, update Google Chrome to version 105.0.5195.125 or later.