Junglewise Threat Intelligence

CVE-2022-2856: Google Chromium Intents Insufficient Input Validation Vulnerability

CVE-2022-2856 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-08-18

Technologies: Google Chrome, Microsoft Edge. Vendors: Opera, Google, Microsoft.

Executive brief

Google Chromium Intents contains an insufficient validation of untrusted input vulnerability. This allows a remote attacker to redirect users to malicious websites via a specially crafted HTML page.

Affected products

  • Google Chrome prior to 104.0.5112.101
  • Microsoft Edge
  • Opera Opera

Timeline

  • 2022-08-16: patched: Stable channel update for desktop released.
  • 2022-08-18: disclosed: CVE published.
  • 2022-08-18: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
  • 2022-08-18: exploited: Reported as exploited in the wild.

Related threats