PT-2022-4584 · Google+1 · Google Chrome+1

Published

2022-08-30

·

Updated

2024-06-15

·

CVE-2022-3050

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome on Chrome OS versions prior to 105.0.5195.52
Description The issue is related to a heap buffer overflow in the WebUI of Google Chrome on Chrome OS. This could allow a remote attacker, who convinces a user to engage in specific UI interactions, to potentially exploit heap corruption via crafted UI interactions. The attacker could execute arbitrary code.
Recommendations For versions prior to 105.0.5195.52, update to version 105.0.5195.52 or later to resolve the issue. As a temporary workaround, consider restricting user interactions with the WebUI to minimize the risk of exploitation.

Fix

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2564
ALT-PU-2022-2611
ALT-PU-2022-2835
ALT-PU-2023-1462
BDU:2022-05461
CVE-2022-3050
DSA-5223-1
MGASA-2022-0318
OPENSUSE-SU-2022:10119-1
OPENSUSE-SU-2022:10120-1
OPENSUSE-SU-2024:12319-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Google Chrome