CVE-2022-1309
About
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Rainforest analyst review
This is a Chrome sandbox escape: insufficient policy enforcement in the browser's developer tools lets a crafted HTML page break out of the renderer sandbox. The sandbox is the wall that contains malicious web content, so an escape means a page a victim merely visits can reach beyond the tab into the broader system. It needs the victim to interact — visiting the page — but requires no privileges and works remotely against any user running a pre-100.0.4896.88 Chrome.
Browser bugs like this are the drive-by attacker's staple: the delivery is just getting someone to load a URL, achievable through phishing, malvertising, or a compromised site. Sandbox escapes are high-value because they're the piece that turns contained web content into real footholds, and they're frequently chained with a renderer bug into a full one-click compromise. Chrome's install base is enormous and mostly on auto-update, which is the saving grace — the patched build rolls out widely and fast — but any user or fleet that lags on updates is exposed to a well-understood, actively-hunted class of flaw.
Browsers are the one place where auto-update usually does our job for us, so our angle is update-coverage assurance rather than heroics. The task is confirming the fleet's Chrome is actually at or past 100.0.4896.88 — auto-update stragglers, managed installs with pinned versions, and machines that rarely restart are where the risk concentrates. We'd rank it by that update-lag population and lean on our endpoint management to force the browser version, since the vendor fix is the fix and reachability is universal.
References
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2022-1309?
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
How severe is CVE-2022-1309?
CVE-2022-1309 carries a CVSS 3.1 base score of 9.6, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 97 out of 100, in the critical band.
How is CVE-2022-1309 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction Required. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-1309?
Public advisories list the following as affected: chrome. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-1309?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
