CVE-2022-0806 is a data leak vulnerability in the Canvas component of Google Chrome, affecting versions prior to 99.0.4844.51, and impacting products from Apple, Google, Linux, and Microsoft. A remote attacker could exploit this by convincing a user to share their screen while viewing a specially crafted HTML page, potentially leading to the leakage of cross-origin data. Rated Medium severity (CVSS 6.5), this vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L), with a high potential for confidentiality impact (C:H). There is no evidence of active exploitation (KEV: No), no public exploit code (Metasploit, Nuclei, ExploitDB: None), and minimal community discussion or media coverage, beyond a mention in a Microsoft Patch Tuesday article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 99.0.4844.51CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.