← back
CVE-2022-1871

CVE-2022-1871

EPSS 0.5%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
27 Jul 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page.
Affected products
Google · Chrome