HIGH
Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
Published Nov 9, 2022
8.8
HIGHCVSS 3.1
EPSS 0.80%
Description
Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected products
-
- Version unspecifiedStatusaffectedConstraints<107.0.5304.106
- Version
Configuration 2
- 11.0
-
- Version 0StatusaffectedConstraints<107.0.5304.106
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop.html Release NotesVendor Advisory
- https://crbug.com/1372695 Permissions RequiredVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43223 Advisory
- https://www.debian.org/security/2022/dsa-5275 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop.html | Release NotesVendor Advisory | |
| https://crbug.com/1372695 | Permissions RequiredVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43223 | Advisory | |
| https://www.debian.org/security/2022/dsa-5275 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Nov 9, 2022
Updated Oct 23, 2024
Reserved Nov 8, 2022
Link CVE-2022-3887
CISA Vulnrichment
Updated Oct 23, 2024
ENISA EUVD
EUVD-2022-43223 Assigner Chrome
Published Nov 9, 2022
Updated Oct 23, 2024
Exploited since n/a
Link EUVD-2022-43223