CVE-2022-1129 is an inappropriate implementation vulnerability in Google Chrome on Android, specifically affecting versions prior to 100.0.4896.60. This flaw allows a remote attacker to spoof the contents of the Omnibox (URL bar) through a crafted HTML page. It carries a CVSS score of 6.5 (Medium), indicating a low attack complexity and the potential for high integrity impact, though it requires user interaction. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 100.0.4896.60CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.