CVE-2022-0807 describes an inappropriate implementation in Google Chrome's Autofill feature (versions prior to 99.0.4844.51) that allowed a remote attacker to bypass navigation restrictions through a specially crafted HTML page. This vulnerability affects products from Apple, Google, Linux, and Microsoft. Rated as Medium severity with a CVSS score of 6.5, it requires user interaction (UI:R) but has low attack complexity (AC:L) and could lead to high integrity impact (I:H). There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 99.0.4844.51CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.