PT-2022-5329 · Google+3 · Google Chrome+3

Sehwa

·

Published

2022-10-25

·

Updated

2026-01-09

·

CVE-2022-3653

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 107.0.5304.62 Chromium versions prior to 107.0.5304.62 Yandex Browser versions prior to 23.1.2.1033-alt1 Chromium-Gost versions prior to 107.0.5304.87-alt1 Chromium-Gost versions prior to 110.0.5481.177-alt1.p10.1 Chromium versions 107.0.5304.68-1~deb11u1 Ungoogled-Chromium versions prior to 113.0.5672.92-1.1 Chromedriver versions prior to 107.0.5304.87-1.1
Description A heap buffer overflow exists in the Vulkan component of Google Chrome, Chromium, Yandex Browser, Chromium-Gost, and related projects. This issue could allow a remote attacker to potentially exploit heap corruption through a specially crafted HTML page. The vulnerability affects the dynamic memory allocation within the Vulkan rendering mode. Exploitation may allow a remote attacker to execute arbitrary code.
Recommendations Google Chrome versions prior to 107.0.5304.62: Upgrade to version 107.0.5304.62 or later. Chromium versions prior to 107.0.5304.62: Upgrade to version 107.0.5304.62 or later. Yandex Browser versions prior to 23.1.2.1033-alt1: Upgrade to version 23.1.2.1033-alt1 or later. Chromium-Gost versions prior to 107.0.5304.87-alt1: Upgrade to version 107.0.5304.87-alt1 or later. Chromium-Gost versions prior to 110.0.5481.177-alt1.p10.1: Upgrade to version 110.0.5481.177-alt1.p10.1 or later. Chromium versions prior to 107.0.5304.68-1deb11u1: Upgrade to version 107.0.5304.68-1deb11u1 or later. Ungoogled-Chromium versions prior to 113.0.5672.92-1.1: Upgrade to version 113.0.5672.92-1.1 or later. Chromedriver versions prior to 107.0.5304.87-1.1: Upgrade to version 107.0.5304.87-1.1 or later.

Fix

RCE

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3011
ALT-PU-2022-3104
ALT-PU-2022-3318
ALT-PU-2023-1462
ALT-PU-2023-1524
ALT-PU-2023-1572
BDU:2022-06634
CVE-2022-3653
DSA-5261-1
MGASA-2022-0419
OPENSUSE-SU-2022:10177-1
OPENSUSE-SU-2022:10180-1
OPENSUSE-SU-2024:12460-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Edge