ZeroHour

CVE-2022-3038

KEV PoC mass

Use-After-Free in Chromium Network Service Affects Chrome, Edge, Opera

CISA: Google Chromium Network Service Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
25%p98
Published
()
KEV added
AI analysis

Google Chromium's Network Service contains a use-after-free vulnerability (CWE-416) that a remote attacker can trigger via a crafted HTML page, potentially causing heap corruption in the browser process. An attacker who successfully exploits the flaw could achieve memory corruption that may lead to browser crashes or arbitrary code execution when a user visits attacker-controlled web content. Any application built on Chromium is potentially affected, including but not limited to Google Chrome, Microsoft Edge, and Opera, meaning the impact spans a very large share of the world's browser users. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2023-03-30, indicating confirmed exploitation in the wild, though ransomware association is unknown and no public proof-of-concept is cataloged. No CVSS score is available yet, but EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile), underscoring elevated exploitation risk.

What to do: Apply browser updates per vendor instructions immediately — update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers deployed in your environment to the latest vendor-supplied patched releases (exact fixed version numbers were not provided in this data; check each vendor's security advisory). Because the flaw is confirmed exploited in the wild and listed in CISA KEV, prioritize patching internet-facing browsing endpoints and users who routinely visit untrusted web content; there are no reliable workarounds beyond patching, though limiting browsing to trusted sites reduces exposure.

Affected
Google Chromium Network Service
Estimated exposure
mass≈3+ billion browser users across Chromium-based browsers (Chrome, Edge, Opera and derivatives) — Chromium powers the world's dominant browsers — Google Chrome alone holds roughly two-thirds of global browser market share with an install base on the order of billions of users — so effectively the entire population of Chromium-based…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium Network Service
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news