CVE-2022-3312: Insufficient validation of untrusted input in VPN
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-3312?
The severity of CVE-2022-3312 is classified as Medium.
How do I fix CVE-2022-3312?
To fix CVE-2022-3312, update Google Chrome or Chromium to version 106.0.5249.61 or higher.
Which systems are affected by CVE-2022-3312?
CVE-2022-3312 affects Google Chrome on ChromeOS prior to version 106.0.5249.62 and certain versions of the Chromium package.
What type of vulnerability is CVE-2022-3312?
CVE-2022-3312 is a vulnerability due to insufficient validation of untrusted input in VPN functionality.
Can physical access allow exploitation of CVE-2022-3312?
Yes, a local attacker with physical access can exploit CVE-2022-3312 to bypass managed device restrictions.