PT-2022-2169 · Google+3 · Google Chrome+3

Guang Gong

+1

·

Published

2022-01-18

·

Updated

2024-06-15

·

CVE-2022-1312

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 100.0.4896.88
Description The issue is related to a use after free in storage, which could allow an attacker to potentially perform a sandbox escape via a crafted Chrome Extension if a user is convinced to install a malicious extension. This could be achieved by exploiting the vulnerability with a specially crafted web page, allowing a remote attacker to execute arbitrary code.
Recommendations For Google Chrome versions prior to 100.0.4896.88, update to version 100.0.4896.88 or later to resolve the issue. As a temporary workaround, consider disabling the installation of extensions from untrusted sources to minimize the risk of exploitation. Restrict access to the storage module to minimize the risk of exploitation until the issue is resolved.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1701
ALT-PU-2022-1734
ALT-PU-2022-1828
ALT-PU-2022-2055
BDU:2022-02178
CVE-2022-1312
DSA-5120-1
MGASA-2022-0146
OPENSUSE-SU-2022_0112-1
OPENSUSE-SU-2024:11988-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Suse