CVE-2022-2613

Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

Published date
2022-08-12T20:15Z
Last modification date
2022-10-27T18:50Z
Assigner
chrome-cve-admin@google.com
Problem type
CWE-416

Impact

CVSS v3 vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NameURLSourceTags
https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop.htmlhttps://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop.htmlMISCVendor Advisory
https://crbug.com/1325256https://crbug.com/1325256MISCIssue Tracking, Permissions Required, Vendor Advisory
GLSA-202208-35https://security.gentoo.org/glsa/202208-35GENTOOThird Party Advisory
FEDORA-2022-3f28aa88cfhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/FEDORAMailing List, Third Party Advisory