← Back to browse · API

CVE-2022-2856

Severity
MEDIUM
CVSS
6.5
EPSS
0.0453
Risk score
52.59
CISA KEV
Yes
PoC
No
Published
2022-09-26
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-35090, GHSA-HQ6M-MWGX-2PR8
Products
Google:Chrome unspecified <104.0.5112.101, Google:Chromium Intents
Sources
euvd EUVD-2022-35090
cisa.gov CVE-2022-2856

Description

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

References