PT-2022-4050 · Google+2 · Google Chrome+3

Chih-Yen Chang

+1

·

Published

2022-08-02

·

Updated

2024-06-15

·

CVE-2022-2624

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 104.0.5112.79
Description The issue is related to a heap buffer overflow in the PDFium PDF content handler, which can be exploited by a remote attacker who convinces a user to engage in specific interactions. This can potentially lead to heap corruption via a crafted PDF file. The attacker could execute arbitrary code.
Recommendations For versions prior to 104.0.5112.79, update to version 104.0.5112.79 or later to resolve the issue. As a temporary workaround, consider avoiding the use of PDF files from untrusted sources until the update is applied.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2564
ALT-PU-2022-2611
ALT-PU-2022-2835
ALT-PU-2023-1462
BDU:2022-04884
CVE-2022-2624
DSA-5201-1
MGASA-2022-0277
OPENSUSE-SU-2022:10086-1
OPENSUSE-SU-2022:10092-1
OPENSUSE-SU-2024:12251-1
OPENSUSE-SU-2024:12291-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Pdfium