CVE-2022-4913: Inappropriate implementation in Extensions
Published Mar 2, 2021
·Updated
Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to spoof extension storage via a crafted HTML page. (Chromium security severity: High)
Credit
Jun Kokatsu, Microsoft Browser Vulnerability Research
Affected Software
2 affected componentsFixes available
Google Chrome<105.0.5195.52
105.0.5195.52
Google Chrome<105.0.5195.52
Event History
Mar 2, 2021
CVE Published
12:00 AM
Jul 28, 2023
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-4913?
The severity of CVE-2022-4913 is classified as High.
2
How do I fix CVE-2022-4913?
To fix CVE-2022-4913, update Google Chrome to version 105.0.5195.52 or later.
3
What type of attack does CVE-2022-4913 allow?
CVE-2022-4913 allows a remote attacker to spoof extension storage through a compromised renderer process.
4
Which versions of Google Chrome are affected by CVE-2022-4913?
CVE-2022-4913 affects all versions of Google Chrome prior to 105.0.5195.52.
5
Who is the vendor associated with CVE-2022-4913?
The vendor associated with CVE-2022-4913 is Google.