CVE-2022-2610 describes an insufficient policy enforcement vulnerability in Google Chrome's Background Fetch feature, affecting versions prior to 104.0.5112.79, as well as Fedora Project's Chrome and Fedora. A remote attacker could exploit this flaw via a crafted HTML page to leak cross-origin data. With a CVSS score of 6.5 (MEDIUM), this vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and could lead to high confidentiality impact (C:H). While not listed on CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, it has garnered some community discussion and media coverage, including a mention in a BleepingComputer article regarding Microsoft's August 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 104.0.5112.79CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.