CERT-In Vulnerability Note
CIVN-2022-0246
Multiple Vulnerabilities in Google Chrome
Original Issue Date:May 25, 2022
Severity Rating: HIGH
Software Affected
- Google Chrome versions prior to 102.0.5005.61
Overview
Multiple vulnerabilities have been reported in Google Chrome which could allow a remote attacker to cause denial of service, bypass implemented security restrictions, gain access to sensitive information, and execute arbitrary code on the targeted systems.
Description
These vulnerabilities exist in Google Chrome due to Use after free in Indexed DB, ANGLE, User Education, Performance Manager, UI Foundations, Sharing, Tab Groups, WebApp Installs, Bookmarks, Tablet Mode, App Service; Out of bounds read in DevTools, Performance Manager; Inappropriate implementation in Extensions, Extensions API; Insufficient validation of untrusted input in Data Transfer, PDF; Type Confusion in V8; Insufficient policy enforcement in File System API, Extensions API, COOP, Safe Browsing and Heap buffer overflow in DevTools. A remote attacker could exploit these vulnerabilities by sending specially crafted requests to the targeted system.
Successful exploitation of these vulnerabilities could allow an attacker to cause denial of service, bypass implemented security restrictions, gain access to sensitive information, and execute arbitrary code on the targeted systems.
Solution
Update to Google Chrome version 102.0.5005.61 as mentioned:
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html
References
Google Chrome
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html
CVE Name
CVE-2022-1853
CVE-2022-1854
CVE-2022-1855
CVE-2022-1856
CVE-2022-1857
CVE-2022-1858
CVE-2022-1859
CVE-2022-1860
CVE-2022-1861
CVE-2022-1862
CVE-2022-1863
CVE-2022-1864
CVE-2022-1865
CVE-2022-1866
CVE-2022-1867
CVE-2022-1868
CVE-2022-1869
CVE-2022-1870
CVE-2022-1871
CVE-2022-1872
CVE-2022-1873
CVE-2022-1874
CVE-2022-1875
CVE-2022-1876
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|