CVE-2022-3312
Published on: Not Yet Published
Last Modified on: 12/08/2022 09:39:00 PM UTC
Certain versions of Chrome from Google contain the following vulnerability:
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)
- CVE-2022-3312 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Google - Chrome version < 106.0.5249.62
CVSS3 Score: 4.6 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
PHYSICAL | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Chrome Releases: Stable Channel Update for Desktop | chromereleases.googleblog.com text/html |
![]() |
1303306 - chromium - An open-source project to help move the web forward. - Monorail | crbug.com text/html |
![]() |
Related QID Numbers
- 181085 Debian Security Update for chromium (DSA 5244-1)
- 377610 Google Chrome Prior to 106.0.5249.61 Multiple Vulnerabilities
- 690946 Free Berkeley Software Distribution (FreeBSD) Security Update for chromium (18529cb0-3e9c-11ed-9bc7-3065ec8fd3ec)
- 710646 Gentoo Linux Chromium, Google Chrome, Microsoft Edge Multiple Vulnerabilities (GLSA 202210-16)
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Chrome | All | All | All | All |
- cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
MS-ISAC CYBERSECURITY ADVISORY – Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution – PATCH: NOW | 2022-09-30 17:59:05 |