PT-2022-2496 · Google+3 · Google Chrome+3

Published

2022-04-26

·

Updated

2024-06-15

·

CVE-2022-1484

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 101.0.4951.41
Description A heap buffer overflow issue in the Web UI Settings of Google Chrome allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. This could lead to arbitrary code execution. The issue is related to the implementation of browser settings in Google Chrome and possibly other browsers like Microsoft Edge, caused by a buffer overflow in dynamic memory.
Recommendations For Google Chrome versions prior to 101.0.4951.41, update to version 101.0.4951.41 or later to resolve the issue. As a temporary workaround, consider restricting access to Web UI Settings until the update is applied. Avoid using crafted HTML pages that could trigger the heap buffer overflow.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1777
ALT-PU-2022-1822
ALT-PU-2022-1828
ALT-PU-2022-2055
BDU:2022-02906
CVE-2022-1484
DSA-5125-1
MGASA-2022-0158
OPENSUSE-SU-2022:0125-1
OPENSUSE-SU-2024:12046-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Edge