Input validation error in Google Chromium - CVE-2022-4925
Published: January 4, 2022 / Updated: August 16, 2023
Vulnerability identifier: #VU79595
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-4925
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to crash the browser.
The vulnerability exists due to a improper input validation in QUIC in Google Chrome. A remote attacker can trick the victim to perform certain actions in browser and crash it.
Affected software
Google Chromium
Google Chrome
Fedora
chromium
Google Chrome
Fedora
chromium
How to mitigate CVE-2022-4925
Update to version 97.0.4692.71.
Google Chromium - update to 97.0.4692.71
Google Chrome - update to 97.0.4692.71
chromium - update to 115.0.5790.170-1.fc38
Google Chrome - update to 97.0.4692.71
chromium - update to 115.0.5790.170-1.fc38