CVE-2022-0806 Canvas data leak allowed remote attackers to potentially leak cross-origin data if a user becomes a screen-sharer.
This issue was addressed by forbidding cross-origin data sharing by default. Screen sharing with untrusted sites was previously possible in Google Chrome. This issue
CVE-2022-0790 An attacker who convinced a user to do specific user interaction can perform a sandbox escape in Google Chrome prior to 99.0.4844.51.
It is possible that similar problems might exist in other products or versions.
CVE-2018-6169 was opened for disclosure on 11/27/2018 and
CVE-2022-0467 Inappropriate Pointer Lock implementation allowed a remote attacker to bypass navigation restrictions.
A warning message about the security warning about the SSL/TLS protocol when accessing a Google site was displayed incorrectly in Pointer Lock in Google
CVE-2022-0464 After free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption by user interaction.
Google applied patch to fix this issue in Accessibility in version 98.0.4758.81. Exploitation of this issue required social engineering with specially crafted
CVE-2022-0454 Heap buffer overflow in ANGLE prior to 98.0.4758.80 allowed a remote attacker to exploit heap corruption.
CVE-2018-6040 had been addressed in this revision. Google informed users via the following security blog post: “An issue was discovered in certain configurations
Episode
00:00:00
00:00:00