CVE-2022-3047 is a medium-severity vulnerability affecting Google Chrome and Fedora Project Chrome prior to version 105.0.5195.52. It stems from insufficient policy enforcement in the Extensions API, allowing an attacker to bypass download policies through a crafted HTML page if a user is tricked into installing a malicious extension. The vulnerability has a CVSS score of 6.5, indicating a network-based attack requiring user interaction, with a potential impact on integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog. While it has received minimal community discussion and media coverage, Microsoft did mention it in their September 2022 Patch Tuesday update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 105.0.5195.52CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.