Vulnerability · NVD
CVE-2022-1128
CVE-2022-1128, medium severity (CVSS 6.5): 2 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 6.5
- Exploitation
- 0.7 %
- Tracked apps
- 2
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
0.69%
above median
percentile 50.2%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Affected <100.0.4896.60 Fixed in 100.0.4896.60 Latest tracked - undetermined
-
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <100.0.4896.60 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | <100.0.4896.60 | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |