CVE-2022-2856

Confirmed PUBLISHED

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily...

Google · Chrome
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
6.5 Medium

At a Glance

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

nessus_scanner cisa android
CVE Published
Sep 26, 2022
Exploitation Reported
Aug 18, 2022
CVSS
6.5 Medium
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
google
chrome

0 to < 104.0.5112.101

Affected
fedoraproject
fedora

37

Affected
Google
Chrome

unspecified to < 104.0.5112.101

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.