PT-2022-2496 · Google+3 · Google Chrome+3
Published
2022-04-26
·
Updated
2024-06-15
·
CVE-2022-1484
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 101.0.4951.41
Description
A heap buffer overflow issue in the Web UI Settings of Google Chrome allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. This could lead to arbitrary code execution. The issue is related to the implementation of browser settings in Google Chrome and possibly other browsers like Microsoft Edge, caused by a buffer overflow in dynamic memory.
Recommendations
For Google Chrome versions prior to 101.0.4951.41, update to version 101.0.4951.41 or later to resolve the issue. As a temporary workaround, consider restricting access to Web UI Settings until the update is applied. Avoid using crafted HTML pages that could trigger the heap buffer overflow.
Exploit
Fix
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Google Chrome
Edge