Cryptographic issues in Google Chromium - CVE-2022-2612

 

Cryptographic issues in Google Chromium - CVE-2022-2612

Published: August 2, 2022 / Updated: August 5, 2022


Vulnerability identifier: #VU65967
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2612
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to side-channel information leak in Keyboard input. Chrome Medium. A remote attacker can create a specially crafted web page, trick the victim into opening it and gain access to sensitive information.


Affected software

Google Chromium
Google Chrome
Microsoft Edge
Gentoo Linux
Debian Linux
Fedora
Chrome OS
www-client/microsoft-edge
chromium (Debian package)
www-client/chromium
www-client/chromium-bin
www-client/google-chrome
chromium

How to mitigate CVE-2022-2612

Update to version 104.0.5112.79.

Google Chromium - update to 104.0.5112.79
Google Chrome - update to 104.0.5112.79
Microsoft Edge - update to 104.0.1293.47
Chrome OS - addressed in versions 96.0.4664.219, 102.0.5005.177
www-client/microsoft-edge - update to 104.0.1293.63
chromium (Debian package) - update to 104.0.5112.79-1~deb11u1
www-client/chromium - update to 104.0.5112.101
www-client/chromium-bin - update to 104.0.5112.101
www-client/google-chrome - update to 104.0.5112.101
chromium - addressed in versions 105.0.5195.125-2.el8, 105.0.5195.125-2.el9, 105.0.5195.125-2.fc35, 105.0.5195.125-2.fc36, 105.0.5195.125-2.fc37

External References

Related Security Bulletins