PT-2022-4294 · Google+2 · Google Chrome+2

Eternalsakura13

+2

·

Published

2022-06-22

·

Updated

2024-06-15

·

CVE-2022-2859

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 104.0.5112.101
Description The issue is related to a use after free in the Chrome OS Shell, which could allow a remote attacker to exploit heap corruption via specific UI interactions if a user is convinced to participate in these interactions. This could potentially lead to the disclosure of protected information using a specially crafted web page.
Recommendations For versions prior to 104.0.5112.101, update to version 104.0.5112.101 or later to resolve the issue. As a temporary workaround, consider restricting interactions with the Chrome OS Shell to minimize the risk of exploitation. Avoid engaging in specific UI interactions that could potentially trigger the heap corruption until the update is applied.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2564
ALT-PU-2022-2611
ALT-PU-2022-2835
ALT-PU-2023-1462
BDU:2022-05150
CVE-2022-2859
DSA-5212-1
MGASA-2022-0307
OPENSUSE-SU-2022:10099-1
OPENSUSE-SU-2022:10108-1
OPENSUSE-SU-2022:10109-1
OPENSUSE-SU-2022_10108-1
OPENSUSE-SU-2022_10109-1
OPENSUSE-SU-2024:12277-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Google Chrome
Suse