CVE-2022-4025: Inappropriate implementation in Paint
Published Oct 15, 2021
·Updated
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
Credit
Suhwan Song
Affected Software
2 affected componentsFixes available
Google Chrome<98.0.4758.80
98.0.4758.80
Google Chrome<98.0.4758.80
Event History
Oct 15, 2021
CVE Published
12:00 AM
Jan 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-4025?
The severity of CVE-2022-4025 is classified as Low by Chrome's security ratings.
2
How do I fix CVE-2022-4025?
To fix CVE-2022-4025, update Google Chrome to version 98.0.4758.80 or later.
3
What impact does CVE-2022-4025 have on users?
CVE-2022-4025 allows a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page.
4
What version of Chrome is affected by CVE-2022-4025?
Google Chrome versions prior to 98.0.4758.80 are affected by CVE-2022-4025.
5
Is there any workaround for CVE-2022-4025?
There are no known workarounds for CVE-2022-4025, the best course of action is to apply the available update.