Spoofing attack in Google Chromium - CVE-2022-4917
Published: June 21, 2022 / Updated: August 16, 2023
Vulnerability identifier: #VU79622
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-4917
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to insufficient validation of user-supplied input in Notifications in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and spoof web page content.
Affected software
Google Chromium
Google Chrome
Fedora
chromium
Google Chrome
Fedora
chromium
How to mitigate CVE-2022-4917
Update to version 103.0.5060.53.
Google Chromium - update to 103.0.5060.53
Google Chrome - update to 103.0.5060.53
chromium - addressed in versions 115.0.5790.170-1.el7, 115.0.5790.170-1.el8, 115.0.5790.170-1.el9, 115.0.5790.170-1.fc38, 115.0.5790.170-2.fc37
Google Chrome - update to 103.0.5060.53
chromium - addressed in versions 115.0.5790.170-1.el7, 115.0.5790.170-1.el8, 115.0.5790.170-1.el9, 115.0.5790.170-1.fc38, 115.0.5790.170-2.fc37