← לוח פגיעויות

CVE-2022-2856

בינונית 6.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Google Chromium Intents Insufficient Input Validation Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS — סבירות ניצול
4% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-20

מוצרים מושפעים

google: chrome; apple: macos; google: android; linux: linux kernel; fedoraproject: fedora; microsoft: windows

קישורים