ZeroHour

CVE-2022-2296

CVSS 3.1
8.8 high
EPSS
1%p63
Published
()
Modified
Description

Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions.

Vendors
googlefedoraproject
Products
chrome, extra packages for enterprise linux, fedora
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news