CVE-2022-3444: Insufficient data validation in File System API
Published May 12, 2021
·Updated
Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page and malicious file. (Chromium security severity: Low)
Credit
Archie Midha & Vallari Sharma
Affected Software
2 affected componentsFixes available
Google Chrome<106.0.5249.61
106.0.5249.61
Google Chrome<106.0.5249.62
Event History
May 12, 2021
CVE Published
12:00 AM
Nov 1, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-3444?
The severity of CVE-2022-3444 is classified as Low.
2
How do I fix CVE-2022-3444?
To fix CVE-2022-3444, update Google Chrome to version 106.0.5249.62 or later.
3
What does CVE-2022-3444 affect?
CVE-2022-3444 affects Google Chrome versions prior to 106.0.5249.62.
4
What type of vulnerability is CVE-2022-3444?
CVE-2022-3444 is an insufficient data validation vulnerability in the File System API.
5
Can CVE-2022-3444 be exploited remotely?
Yes, CVE-2022-3444 can be exploited remotely via a crafted HTML page and malicious file.