CVE-2022-3875 is a critical authentication bypass vulnerability affecting Click Studios Passwordstate and its Chrome Browser Extension, specifically within an unknown API component. This flaw allows remote attackers to bypass authentication due to assumed-immutable data, potentially leading to unauthorized access to sensitive information (CVSS 7.5 HIGH). While there is no evidence of active exploitation in the wild (KEV: No), the exploit has been publicly disclosed, and the vulnerability has garnered some community discussion and media coverage, indicating awareness among threat actors. Users are strongly advised to upgrade affected components immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:clickstudios:passwordstate:-:*:*:*:*:-:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:clickstudios:passwordstate:-:*:*:*:*:chrome:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.