CVE-2022-0455 describes an inappropriate implementation in Google Chrome's Full Screen Mode on Android, affecting versions prior to 98.0.4758.80. This vulnerability allows a remote attacker to spoof the Omnibox (URL bar) by tricking a user into visiting a specially crafted HTML page. The vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited over the network with low attack complexity, requiring user interaction to achieve a high impact on integrity. There is no evidence of active exploitation, nor are there known public exploits or Metasploit modules, although it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 98.0.4758.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.