CVE-2022-2615 is a medium-severity vulnerability in Google Chrome, affecting versions prior to 104.0.5112.79, as well as related Fedora products. This flaw, categorized as insufficient policy enforcement in cookies, allows a remote attacker to leak cross-origin data through a specially crafted HTML page. The vulnerability has a CVSS score of 6.5, indicating a network-based attack requiring user interaction, with a high impact on confidentiality. There is no evidence of active exploitation (KEV list), nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Despite limited community discussion, it has received some media coverage, notably in Microsoft's August 2022 Patch Tuesday reporting.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 104.0.5112.79CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.