CVE-2022-0291 is a medium-severity vulnerability affecting Google Chrome versions prior to 97.0.4692.99. It involves an inappropriate implementation in the Storage component, allowing a remote attacker to bypass site isolation through a crafted HTML page if they have already compromised the renderer process. The attack requires user interaction (UI:R) and could lead to high confidentiality impact (C:H). There is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 97.0.4692.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.