Vulnerability record · CVE-2022-2856 · published 26 September 2022
CVE-2022-2856: Google Chrome Android Intents input validation flaw enables forced browsing
Google · Chrome
Chrome on Android before 104.0.5112.101 fails to properly validate untrusted input passed through Intents, allowing a crafted HTML page to direct the browser to an arbitrary website. The flaw is an input validation weakness (CWE-20) that matters because it was exploited in the wild and added to CISA's KEV catalog.
Description
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Automated analysis
high priorityThe flaw is confirmed exploited in CISA KEV and affects a widely deployed browser, though its CVSS score is only 6.5 and impact is limited to forced navigation.
What it is
Chrome on Android before 104.0.5112.101 fails to properly validate untrusted input passed through Intents, allowing a crafted HTML page to direct the browser to an arbitrary website. The flaw is an input validation weakness (CWE-20) that matters because it was exploited in the wild and added to CISA's KEV catalog.
Impact
An attacker can force the victim's browser to navigate to an attacker-chosen website, enabling redirection to malicious or phishing content. Integrity impact is rated High; there is no confidentiality or availability impact in the CVSS vector.
Attack surface
Reached over the network via a crafted HTML page that triggers the Intents handling path; no privileges are required but user interaction is required per the CVSS vector (UI:R). The description does not detail the exact Intent or component involved.
Exploitation
CISA KEV lists it as exploited, with a due date of 2022-09-08, and a reference is tagged Exploit. EPSS 30-day probability is 0.0453 (91st percentile), indicating elevated but not top-tier predicted activity.
What to do
- Update Chrome on Android to 104.0.5112.101 or later, and apply the Fedora package update for Chromium.
- Enforce automatic browser updates and verify deployed versions across managed Android devices.
- Restrict or monitor outbound browsing to untrusted sites through web filtering or DNS controls.
- Treat the CVE as exploited in the wild and prioritize remediation over routine patch cycles.
Detection
- Review Chrome/Chromium version inventory for Android devices below 104.0.5112.101.
- Monitor proxy, DNS or firewall logs for unexpected redirects or navigation to low-reputation domains from Android Chrome clients.
- Hunt for phishing or forced-browsing reports correlated with crafted HTML pages or Intent-triggering links.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-2856 to the Known Exploited Vulnerabilities catalog on 18 August 2022 as "Google Chromium Intents Insufficient Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 8 September 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html | PatchRelease NotesVendor Advisory |
| https://crbug.com/1345630 | ExploitIssue TrackingMailing ListVendor Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z | Mailing List |
| https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html | PatchRelease NotesVendor Advisory |
| https://crbug.com/1345630 | ExploitIssue TrackingMailing ListVendor Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z | Mailing List |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-2856 | US Government Resource |
Track CVE-2022-2856 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-2856), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.