CVE-2022-3310

Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: Medium)
References
Link Resource
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html Release Notes Vendor Advisory
https://crbug.com/1240065 Exploit Issue Tracking Vendor Advisory
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html Release Notes Vendor Advisory
https://crbug.com/1240065 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

History

06 May 2025, 16:15

Type Values Removed Values Added
CWE CWE-602

21 Nov 2024, 07:19

Type Values Removed Values Added
References () https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html - Release Notes, Vendor Advisory () https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html - Release Notes, Vendor Advisory
References () https://crbug.com/1240065 - Exploit, Issue Tracking, Vendor Advisory () https://crbug.com/1240065 - Exploit, Issue Tracking, Vendor Advisory

10 Nov 2022, 00:15

Type Values Removed Values Added
Summary Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chrome security severity: Medium) Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: Medium)

02 Nov 2022, 17:41

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
References (MISC) https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html - (MISC) https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html - Release Notes, Vendor Advisory
References (MISC) https://crbug.com/1240065 - (MISC) https://crbug.com/1240065 - Permissions Required, Vendor Advisory

01 Nov 2022, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-01 20:15

Updated : 2025-05-06 16:15


NVD link : CVE-2022-3310

Mitre link : CVE-2022-3310

CVE.ORG link : CVE-2022-3310


JSON object : View

Products Affected

google

  • chrome
  • android
CWE
NVD-CWE-noinfo CWE-602

Client-Side Enforcement of Server-Side Security