CVE-2022-3048 describes an inappropriate implementation in the Chrome OS lockscreen, affecting Google Chrome on Chrome OS prior to version 105.0.5195.52, as well as various Fedora Project distributions. This vulnerability allows a local attacker with physical access to bypass lockscreen navigation restrictions. It carries a CVSS v3.1 score of 6.8 (Medium), indicating a physical attack vector with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting a low profile for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 105.0.5195.52CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.