CVE-2022-3447 describes an inappropriate implementation in Google Chrome's Custom Tabs feature on Android, affecting versions prior to 106.0.5249.119. This vulnerability allows a remote attacker to spoof the Omnibox (URL bar) content through a specially crafted HTML page. It has a CVSS score of 4.3 (Medium), indicating a low impact on integrity and requiring user interaction, but is easily exploitable over the network. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it received limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 106.0.5249.119CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.