![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1871 – Debian Security Advisory 5148-1
https://notcve.org/view.php?id=CVE-2022-1871
28 May 2022 — Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page. Una aplicación insuficiente de políticas en File System API en Google Chrome versiones anteriores a 102.0.5005.61, permitía a un atacante que convencía a un usuario de instalar una extensión maliciosa para eludir la política del sistema de archivos por medio de una página HTML diseñada Multip... • https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1872 – Debian Security Advisory 5148-1
https://notcve.org/view.php?id=CVE-2022-1872
28 May 2022 — Insufficient policy enforcement in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page. Una aplicación insuficiente de políticas en Extensions API en Google Chrome versiones anteriores a 102.0.5005.61, permitía a un atacante que convenciera a un usuario de instalar una extensión maliciosa omitir la política de descargas por medio de una página HTML diseñada Multiple vulnerabilities... • https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1875 – Debian Security Advisory 5148-1
https://notcve.org/view.php?id=CVE-2022-1875
28 May 2022 — Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Una implementación inapropiada en PDF en Google Chrome versiones anteriores a 102.0.5005.61, permitía a un atacante remoto filtrar datos de origen cruzado por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution. Versions less than 5.15.5_p2022061... • https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html • CWE-668: Exposure of Resource to Wrong Sphere •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1138 – Gentoo Linux Security Advisory 202208-25
https://notcve.org/view.php?id=CVE-2022-1138
28 Apr 2022 — Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page. Una implementación inapropiada de Web Cursor en Google Chrome versiones anteriores a 100.0.4896.60, permitía a un atacante remoto que hubiera comprometido el proceso de renderización ocultar el contenido de la Omnibox (barra de URL) por medio de una página HTML diseñada Multiple vulnerab... • https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.html • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1136 – Gentoo Linux Security Advisory 202208-25
https://notcve.org/view.php?id=CVE-2022-1136
28 Apr 2022 — Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific set of user gestures. Un Uso de memoria previamente liberada en Tab Strip en Google Chrome versiones anteriores a 100.0.4896.60, permitía a un atacante que convencía a un usuario de instalar una extensión maliciosa explotar potencialmente la corrupción de la pila por medio de un conjunto específico de gestos del usua... • https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.html • CWE-416: Use After Free •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1130 – Gentoo Linux Security Advisory 202208-25
https://notcve.org/view.php?id=CVE-2022-1130
28 Apr 2022 — Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to send arbitrary intents from any app via a malicious app. Una comprobación insuficiente de la entrada confiable en WebOTP en Google Chrome en Android versiones anteriores a 100.0.4896.60, permitía a un atacante remoto enviar intenciones arbitrarias desde cualquier aplicación por medio de una aplicación maliciosa Multiple vulnerabilities have been found in Chromium and its derivativ... • https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.html • CWE-476: NULL Pointer Dereference •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1308 – Gentoo Linux Security Advisory 202208-25
https://notcve.org/view.php?id=CVE-2022-1308
28 Apr 2022 — Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Un uso de memoria previamente liberada en BFCache en Google Chrome versiones anteriores a 100.0.4896.88, permitía a un atacante remoto explotar potencialmente la corrupción de la pila por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution. Ve... • https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_11.html • CWE-416: Use After Free •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1311 – Gentoo Linux Security Advisory 202208-25
https://notcve.org/view.php?id=CVE-2022-1311
28 Apr 2022 — Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Un uso de memoria previamente liberada en shell en Google Chrome en ChromeOS versiones anteriores a 100.0.4896.88, permitía a un atacante remoto explotar potencialmente la corrupción de la pila por medio de una página HTML diseñada Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remot... • https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_11.html • CWE-416: Use After Free •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1486 – Gentoo Linux Security Advisory 202208-25
https://notcve.org/view.php?id=CVE-2022-1486
28 Apr 2022 — Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Una confusión de tipo en V8 en Google Chrome versiones anteriores a 101.0.4951.41, permitía a un atacante remoto conseguir información potencialmente confidencial de la memoria del proceso por medio de una página HTML diseñada. Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in... • https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-1477 – Gentoo Linux Security Advisory 202208-25
https://notcve.org/view.php?id=CVE-2022-1477
28 Apr 2022 — Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Un uso de memoria previamente liberada en Vulkan en Google Chrome versiones anteriores a 101.0.4951.41, permitía a un atacante remoto explotar potencialmente la corrupción de la pila por medio de una página HTML diseñada. Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution. Ver... • https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html • CWE-416: Use After Free •