CVE-2022-0117 describes a policy bypass vulnerability in Google Chrome's Blink rendering engine, affecting versions prior to 97.0.4692.71, as well as Fedora Project's Chrome and Fedora distributions. This medium-severity flaw (CVSS 6.5) allows a remote attacker to leak cross-origin data through a crafted HTML page, requiring user interaction but with high confidentiality impact. While not listed in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, including mention in Microsoft's January 2022 Patch Tuesday summary.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 97.0.4692.71CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.