CVE-2022-3313 is a medium-severity vulnerability affecting Google Chrome versions prior to 106.0.5249.62. It allows a remote attacker to spoof security UI elements through a crafted HTML page due to incorrect security UI handling in full-screen mode. The vulnerability has a CVSS score of 6.5, indicating high integrity impact and requiring user interaction, but with low attack complexity. There is no public exploit code available, nor is it listed in CISA's KEV catalog, suggesting it is not actively exploited, despite limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 106.0.5249.62CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.