HIGH

CVE-2022-3038

Google Chrome 2022-09-26 CVSS v3.1
CVSS
8.8
KEV

Description

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Summary dbcve.org

A use-after-free vulnerability exists in the Network Service component of Google Chrome versions prior to 105.0.5195.52. This memory safety flaw allows a remote attacker to trigger heap corruption through a specially crafted HTML page, potentially leading to arbitrary code execution.

Mitigation

Update Google Chrome to version 105.0.5195.52 or later to remediate this vulnerability. Organizations should deploy the update via their patch management infrastructure and verify complete coverage.

Proof of Concept

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

24.74%
Probability of exploitation in next 30 days
97.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE