PT-2022-4612 · Google+2 · Google Chrome+2

Sergei Glazunov

·

Published

2022-08-16

·

Updated

2023-03-18

·

CVE-2022-2998

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 104.0.5112.101
Description The issue is related to a use after free in Browser Creation, which could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page if the user engages in a specific UI interaction. This could lead to arbitrary code execution.
Recommendations For Google Chrome versions prior to 104.0.5112.101, update to version 104.0.5112.101 or later to resolve the issue.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2564
ALT-PU-2022-2611
ALT-PU-2022-2835
ALT-PU-2023-1462
BDU:2022-05490
CVE-2022-2998
DSA-5212-1

Affected Products

Alt Linux
Astra Linux
Google Chrome