CVE-2022-3310
Summary
| CVE | CVE-2022-3310 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-01 20:15:00 UTC |
| Updated | 2022-12-09 15:48:00 UTC |
| Description | Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: Medium) |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1240065 - chromium - An open-source project to help move the web forward. - Monorail | MISC | crbug.com | |
| Chrome Releases: Stable Channel Update for Desktop | MISC | chromereleases.googleblog.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181085 Debian Security Update for chromium (DSA 5244-1)
- 183788 Debian Security Update for chromium (CVE-2022-3310)
- 377610 Google Chrome Prior to 106.0.5249.61 Multiple Vulnerabilities
- 377613 Microsoft Edge Based on Chromium Prior to 106.0.1370.34 Multiple Vulnerabilities
- 630864 For ios Vulnerability CVE-2022-3310
- 690946 Free Berkeley Software Distribution (FreeBSD) Security Update for chromium (18529cb0-3e9c-11ed-9bc7-3065ec8fd3ec)
- 710646 Gentoo Linux Chromium, Google Chrome, Microsoft Edge Multiple Vulnerabilities (GLSA 202210-16)