CVE-2022-4908: Inappropriate implementation in iFrame Sandbox
Published Sep 2, 2022
·Updated
Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Credit
Johan Carlsson@@joaxcar
Affected Software
2 affected componentsFixes available
Google Chrome<107.0.5304.62
107.0.5304.62
Google Chrome<107.0.5304.62
Event History
Sep 2, 2022
CVE Published
12:00 AM
Jul 28, 2023
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-4908?
CVE-2022-4908 has a medium severity rating according to Chromium security standards.
2
How do I fix CVE-2022-4908?
To fix CVE-2022-4908, update Google Chrome to version 107.0.5304.62 or later.
3
What causes the vulnerability in CVE-2022-4908?
CVE-2022-4908 is caused by an inappropriate implementation of the iFrame Sandbox in Google Chrome.
4
What type of attack can be executed using CVE-2022-4908?
CVE-2022-4908 allows remote attackers to leak cross-origin data via a crafted HTML page.
5
Which versions of Google Chrome are affected by CVE-2022-4908?
Google Chrome versions prior to 107.0.5304.62 are affected by CVE-2022-4908.