Back to Labs
Security Advisory

CVE-2022-3443

About

Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page. (Chromium security severity: Low)

Rainforest analyst review

This is a File System API validation gap in Chrome: a crafted page can slip past some of the restrictions the API is supposed to enforce. It needs the victim to actually load the malicious page, and even Chromium's own triage rated the severity Low. Nothing here grants code execution or data theft on its own; it loosens a boundary that other things would have to build on.

Flaws like this almost never see opportunistic exploitation. There is no unauthenticated server to spray, the payoff is marginal, and browser sandbox-adjacent bugs of Low severity are not what commodity actors bother weaponizing. Chrome's silent auto-update also means the vulnerable window closes on its own for the vast majority of users within days of the stable release that carries the fix.

We would rank this well below its 4.3 and let the browser's update channel do the work. Our only real action is confirming that managed Chrome fleets aren't pinned to an old build past 106.0.5249.62 by some enterprise policy; where auto-update is intact, this needs no dedicated attention from us.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2022-3443?

Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page. (Chromium security severity: Low)

How severe is CVE-2022-3443?

CVE-2022-3443 carries a CVSS 3.1 base score of 4.3, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 49 out of 100, in the moderate band.

How is CVE-2022-3443 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N): attack vector Network, attack complexity Low, privileges required None, user interaction Required. Impact on confidentiality None, integrity Low and availability None.

Which products are affected by CVE-2022-3443?

Public advisories list the following as affected: chrome. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2022-3443?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email