PT-2022-26058 · Google+2 · Google Chrome+3
Published
2022-11-29
·
Updated
2024-06-15
·
CVE-2022-4176
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lacros versions prior to 108.0.5359.71
Google Chrome on Chrome OS versions prior to 108.0.5359.71
Description
The issue involves an out of bounds write in Lacros Graphics, allowing a remote attacker to potentially exploit heap corruption via UI interactions if a user is convinced to engage in specific UI interactions.
Recommendations
For Lacros versions prior to 108.0.5359.71, update to version 108.0.5359.71 or later.
For Google Chrome on Chrome OS versions prior to 108.0.5359.71, update to version 108.0.5359.71 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Google Chrome
Lacros