HIGH
CVE-2022-3038
CVSS
8.8
KEV
Description
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Summary dbcve.org
A use-after-free vulnerability exists in the Network Service component of Google Chrome versions prior to 105.0.5195.52. This memory safety flaw allows a remote attacker to trigger heap corruption through a specially crafted HTML page, potentially leading to arbitrary code execution.
Mitigation
Update Google Chrome to version 105.0.5195.52 or later to remediate this vulnerability. Organizations should deploy the update via their patch management infrastructure and verify complete coverage.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
24.74%
Probability of exploitation in next 30 days
97.8th percentile
References
http://packetstormsecurity.com/files/168596/Google-Chrome-103.0.5060.53-network-URLLoader-NotifyCompleted-Heap-Use-After-Free.html
Third Party Advisory, VDB Entry
https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_30.html
Release Notes, Vendor Advisory
https://crbug.com/1340253
Exploit, Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/
Mailing List
https://security.gentoo.org/glsa/202209-23
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-3038
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.