PT-2022-6192 · Google+2 · Google Chrome+3

Published

2022-11-29

·

Updated

2024-06-15

·

CVE-2022-4180

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 108.0.5359.71
Description The issue is related to a use-after-free vulnerability in the Mojo library of Google Chrome, which could allow an attacker to potentially exploit heap corruption via a crafted Chrome Extension if a user is convinced to install a malicious extension. The severity of this issue is considered high.
Recommendations For versions prior to 108.0.5359.71, update to version 108.0.5359.71 or later to resolve the issue. As a temporary workaround, consider restricting the installation of extensions to only trusted sources until the update is applied.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3280
ALT-PU-2023-1245
ALT-PU-2023-1410
ALT-PU-2023-1462
ALT-PU-2023-1524
ALT-PU-2023-1572
BDU:2023-00400
CVE-2022-4180
DSA-5293-1
MGASA-2022-0451
OPENSUSE-SU-2022:10229-1
OPENSUSE-SU-2024:12545-1
OPENSUSE-SU-2024:12590-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Astra Linux
Google Chrome
Mojo