CVE-2022-2622 describes an insufficient input validation vulnerability in Google Chrome's Safe Browsing feature on Windows, affecting versions prior to 104.0.5112.79. This flaw allows a remote attacker to bypass download restrictions using a specially crafted file, impacting various Google Chrome and Fedora Project installations on Windows. With a CVSS score of 6.5 (MEDIUM), this vulnerability requires user interaction (UI:R) but can be exploited over the network (AV:N) with low attack complexity (AC:L). The primary impact is a high integrity loss (I:H), meaning an attacker could potentially manipulate or bypass security controls related to downloads, though confidentiality and availability are not directly affected. While there is no evidence of active exploitation (KEV: No) and no public exploit code available (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 104.0.5112.79CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.