ZeroHour

CVE-2022-2856

KEV PoC mass

Intents Input Validation Flaw in Google Chrome for Android (CVE-2022-2856)

CISA: Google Chromium Intents Insufficient Input Validation Vulnerability

CVSS 3.1
6.5 medium
EPSS
5%p91
Published
()
KEV added
AI analysis

CVE-2022-2856 is an insufficient input validation flaw (CWE-20) in the Intents component of Google Chrome on Android. A remote attacker can trigger it by convincing a user to open a crafted HTML page, requiring no privileges beyond user interaction. On success, the attacker can make the victim's browser arbitrarily browse to a malicious, attacker-chosen website, an integrity impact (CVSS 3.1: 6.5, AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N). It affects Chrome on Android prior to 104.0.5112.101, and Fedora's chromium packages were also affected per the CPE data. The flaw is being exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-18, with headlines indicating it was the ninth actively exploited Chrome zero-day patched by Google in 2022.

What to do: Update Chrome on Android to 104.0.5112.101 or later (check via Chrome's About page or the Play Store) and apply the updated Fedora chromium packages as they are released, per the CISA KEV required action. Verify fleet versions for managed Android/Chrome deployments and confirm no devices remain below 104.0.5112.101. Until patched, treat links from untrusted sources with caution since exploitation requires user interaction with a crafted page.

Affected
google chromeChrome on Android prior to 104.0.5112.101
fedoraproject fedoraFedora chromium builds prior to the 104.0.5112.101 fix (Fedora package version numbers not specified in the data)
Estimated exposure
mass≈1 billion+ Chrome-on-Android installations that were unpatched at the time of disclosure — Chrome is the dominant mobile browser with billions of Android users, so the vulnerable install base ahead of the 104.0.5112.101 auto-update rollout was on the order of a billion or more devices; Fedora chromium install counts are not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium Intents
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news