CERT-In Vulnerability Note
CIVN-2022-0071
Multiple Vulnerabilities in Google Chrome OS
Original Issue Date:February 08, 2022
Severity Rating: HIGH
Software Affected
- Google Chrome OS versions prior to 96.0.4664.180
Overview
Multiple vulnerabilities have been reported in Google Chrome OS which could be exploited by a remote attacker to bypass security restrictions, execute arbitrary code or cause denial of service condition on the targeted system.
Description
Multiple vulnerabilities exist in Google Chrome OS due to integer overflow in the gmp plugin, inappropriate implementation in Autofill, Storage, Push messaging, Fenced Frames and Service Worker API, use-after-free in Storage, Safe browsing, Scheduling, Printing, Omnibox, Web packaging, Site isolation, Bookmarks, Text Input Method Editor and Optimization Guide, improper bounds checking by PDFium and Task Manager. An attacker could exploit this vulnerability by enticing the victim to open the specially crafted webpage.
Successful exploitation of this vulnerability could allow a remote attacker to bypass security restriction, execute arbitrary code or cause denial of service condition on the targeted system.
Solution
Apply appropriate updates as mentioned
https://chromereleases.googleblog.com/2022/02/long-term-support-channel-update.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2022/02/long-term-support-channel-update.html
References
Google Chrome
https://chromereleases.googleblog.com/2022/02/long-term-support-channel-update.html
CVE Name
CVE-2021-41990
CVE-2022-0096
CVE-2022-0109
CVE-2022-0289
CVE-2022-0290
CVE-2022-0291
CVE-2022-0292
CVE-2022-0293
CVE-2022-0294
CVE-2022-0295
CVE-2022-0296
CVE-2022-0298
CVE-2022-0300
CVE-2022-0302
CVE-2022-0304
CVE-2022-0305
CVE-2022-0306
CVE-2022-0307
CVE-2022-0309
CVE-2022-0310
CVE-2022-0311
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|